MyBB CVE-2015-2334 Cross Site Request Forgery Vulnerability
BID:73214
Info
MyBB CVE-2015-2334 Cross Site Request Forgery Vulnerability
| Bugtraq ID: | 73214 |
| Class: | Input Validation Error |
| CVE: |
CVE-2015-2334 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 19 2015 12:00AM |
| Updated: | Mar 19 2015 12:00AM |
| Credit: | Devilshakerz |
| Vulnerable: |
MyBB MyBB 1.6.8 MyBB MyBB 1.6.7 MyBB MyBB 1.6.6 MyBB MyBB 1.6.5 MyBB MyBB 1.6.4 MyBB MyBB 1.6.3 MyBB MyBB 1.6.2 MyBB MyBB 1.6.1 MyBB MyBB 1.4.16 MyBB MyBB 1.4.15 MyBB MyBB 1.4.14 MyBB MyBB 1.4.10 MyBB MyBB 1.4.9 MyBB MyBB 1.4.8 MyBB MyBB 1.4.7 MyBB MyBB 1.4.6 MyBB MyBB 1.4.5 MyBB MyBB 1.4.3 MyBB MyBB 1.4.2 MyBB MyBB 1.2.14 MyBB MyBB 1.2.12 MyBB MyBB 1.2.2 MyBB MyBB 1.2.1 MyBB MyBB 1.2 MyBB MyBB 1.1.3 MyBB MyBB 1.1 MyBB MyBB 1.6 |
| Not Vulnerable: | |
Discussion
MyBB CVE-2015-2334 Cross Site Request Forgery Vulnerability
MyBB is prone to a cross-site request-forgery vulnerability.
An attacker may exploit this issue to perform certain unauthorized actions. This may lead to further attacks.
Versions prior to MyBB 1.8.4 are vulnerable.
MyBB is prone to a cross-site request-forgery vulnerability.
An attacker may exploit this issue to perform certain unauthorized actions. This may lead to further attacks.
Versions prior to MyBB 1.8.4 are vulnerable.
Exploit / POC
MyBB CVE-2015-2334 Cross Site Request Forgery Vulnerability
To exploit this issue an attacker must entice a user into visiting a malicious site.
To exploit this issue an attacker must entice a user into visiting a malicious site.
Solution / Fix
MyBB CVE-2015-2334 Cross Site Request Forgery Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.