|
Brought to you by:
Suppliers of:
|
|
|
| |
MyBB suffers from failure to properly sanitize user input, resulting in cross-site-scripting vulnerabilities.
By entering malicious scripts into the Avatar URL field in the user control panel, attackers can steal login credentials, attack user pcs, manipulate board settings and even to introduce malicious php scripts into the board. |
| |
Credit:
The information has been provided by Jacques Copeau.
|
| |
Vulnerable Systems:
* MyBB version 1.4.5 and earlier
Immune Systems:
* * MyBB version 1.4.6
The XSS renders in all browsers and on various pages inside the myBB software. We consider it to be particularly grave, as it renders on the ACP user overview page; this can be easily exploited to construct a universal CSRF vulnerability that introduces malicious php code into the script.
Disclosure Timeline:
April 29th 2009: Contacted Vendor
April 30th 2009: Vendor reaction: "bogus"
April 30th 2009: Vendor corrects statement
May 3rd 2009: Patch released
May 3rd 2009: Full Disclosure
|
|
|
|
|