The OpenNET Project
 
Search (keywords):  SOFT ARTICLES TIPS & TRICKS SECURITY
LINKS NEWS MAN DOCUMENTATION


MyBB 1.0.2 SQL injection


<< Previous INDEX Search src / Print Next >>
Date: 13 Jan 2006 11:37:01 -0000
From: [email protected]
To: [email protected]
Subject: MyBB 1.0.2 SQL injection
X-Virus-Scanned: antivirus-gw at tyumen.ru

Hey
this is a bug report for mybb software ( forum software downloadable from http://www.mybboard.com)
bug found by imei;
bug is in usercp.php file line 830 (ver 1.0.2 latest ver) that allows SQL injection
bug is in result of poor checking for $mybb->input['threadmode'] value that can have quote and can change other fields' values and may result to full access to admin cp (by injecting usergroup field)
bug is reported to vendor and perhaps they will patched it soon.

bests
imei


<< Previous INDEX Search src / Print Next >>



Партнёры:
PostgresPro
Inferno Solutions
Hosting by Hoster.ru
Хостинг:

Закладки на сайте
Проследить за страницей
Created 1996-2025 by Maxim Chirkov
Добавить, Поддержать, Вебмастеру