|
|
|
|
| |
Credit:
The original article can be found at: http://www.securityfocus.com/bid/4721
|
| |
Vulnerable Systems:
* MyBB DevBB 1.0
The first involves 'member.php'; submitting script to the variable 'member' in the context of 'action=viewpro' (profile viewing) will cause that script to be returned as an error message.
The second involves the 'MSN' information field of a user profile; a registered user can submit script to this field without it being filtered.
The third issue can be exploited by submitting a '<script>' tag encoded as '%253Cscript%253E' (note that the percent sign is encoded as '%25', and '3C' and '3E' are the '<' and '>' brackets) to the username variable in the context of 'action=reg' to 'member.php'.
Vendor Status:
MyBB as issued an update for this vulnerablity
Patch Availability:
http://www.mybb.com/downloads
CVE Information:
CVE-2007-6728
Disclosure Timeline:
Initial Release May 11 2002
|
|
|
|
|