Vulnerable Systems:
* MyBB versions 1.4.11 and earlier
Immune Systems:
* MyBB version 0.9.30
* MyBB version 1.4.12
This allows an attacker to takeover accounts via the password reset functionality.
During evaluation of various password reset implementations it was discovered that MyBB contains an email injection vulnerability that allows arbitrary account takeover by injecting BCC: email headers through a simple URL manipulation.
When triggering the password reset functionality via such a manipulated URL MyBB will send a copy of the secret password reset email to wherever the injected BCC: header points to.
Disclosure Timeline:
31. March 2010 - Notified the MyBB devs via security contact form
13. April 2010 - MyBB developers released MyBB 1.4.12
13. April 2010 - Public Disclosure