Bugtraq mailing list archives
Re: MyBB 1.4.2: Multiple Vulnerabilties
From: krzysztof.kozlowski () kozik net pl
Date: Mon, 27 Oct 2008 15:14:29 -0600
And a solution for first bug (XSS): File: functions.php, function redirect() FIND: ---------------- function redirect($url, $message="", $title="") { global $header, $footer, $mybb, $theme, $headerinclude, $templates, $lang, $plugins; $redirect_args = array(url => &$url, message => &$message, title => &$title); $plugins->run_hooks_by_ref(redirect, $redirect_args); if($mybb->input['ajax']) ---------------- REPLACE WITH: ---------------- function redirect($url, $message="", $title="") { global $header, $footer, $mybb, $theme, $headerinclude, $templates, $lang, $plugins; $redirect_args = array(url => &$url, message => &$message, title => &$title); $plugins->run_hooks_by_ref(redirect, $redirect_args); $url = addslashes($url) ; if($mybb->input['ajax']) ----------------
Current thread:
- MyBB 1.4.2: Multiple Vulnerabilties Micheal Cottingham (Oct 27)
- <Possible follow-ups>
- Re: MyBB 1.4.2: Multiple Vulnerabilties krzysztof . kozlowski (Oct 27)