vendor:
MyBB
by:
Janek Vind 'waraxe'
7.5
CVSS
HIGH
Remote Code Execution
94
CWE
Product Name: MyBB
Affected Version From: 1.2.10
Affected Version To: 1.2.10
Patch Exists: Yes
Related CWE: N/A
CPE: a:mybb:mybb:1.2.10
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
Remote Code Execution in MyBB 1.2.10
MyBB is a discussion board that has been around for a while; it has evolved from other bulletin boards into the forum package it is today. Two vulnerabilities were discovered in MyBB 1.2.10, one in the forumdisplay.php file and one in the search.php file. Both vulnerabilities allow for remote code execution, with the precondition that the attacker knows the valid forum 'fid' or search 'sid'. Attackers do not need to have any privileges in the MyBB installation to be successful in the attack. Proof-of-concept requests are provided in the text.
Mitigation:
Upgrade to the latest version of MyBB, which is 1.8.22.