MyBB 'posthash' Parameter SQL Injection Vulnerability
BID:56960
Info
MyBB 'posthash' Parameter SQL Injection Vulnerability
| Bugtraq ID: | 56960 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 17 2012 12:00AM |
| Updated: | Dec 17 2012 12:00AM |
| Credit: | frostschutz and StefanT |
| Vulnerable: |
MyBB MyBB 1.6.8 MyBB MyBB 1.6.7 MyBB MyBB 1.6.6 MyBB MyBB 1.6.5 MyBB MyBB 1.6.4 MyBB MyBB 1.6.3 MyBB MyBB 1.6.2 MyBB MyBB 1.6.1 MyBB MyBB 1.6 |
| Not Vulnerable: | |
Discussion
MyBB 'posthash' Parameter SQL Injection Vulnerability
MyBB is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit may allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database.
MyBB versions prior to 1.6.9 are vulnerable.
MyBB is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit may allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database.
MyBB versions prior to 1.6.9 are vulnerable.
Exploit / POC
MyBB 'posthash' Parameter SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.