Bugtraq: [waraxe-2008-SA#061] - Remote Code Execution in MyBB 1.2.10

[waraxe-2008-SA#061] - Remote Code Execution in MyBB 1.2.10


Related Files:

  • http://packetstormsecurity.com/papers/call_for/confidence-2008-cfp.txt

    Call for papers for the 4th edition of the best Polish IT security conference, CONFIDENCE 2008, which is taking place on May 16th and May 17th, 2008.  Homepage: http://2008.confidence.org.pl/.

  • http://packetstormsecurity.com/0405-advisories/waraxe-2004-SA026.txt

    Multiple vulnerabilities in Coppermine Photo Gallery version 1.2.2b for PhpNuke. These range from small flaws like path disclosure, cross site scripting, and arbitrary directory browsing, to remote command execution on the underlying server.  Homepage: http://www.waraxe.us/. Authored By Janek Vind aka waraxe

  • http://packetstormsecurity.com/0404-advisories/waraxe-2004-SA019.txt

    A critical SQL injection bug exists in Phorum version 3.4.7 that allows a remote attacker to view sensitive data. The problem code lies in userlogin.php. Related exploit here.  Homepage: http://www.waraxe.us/. Authored By Janek Vind aka waraxe

  • http://packetstormsecurity.com/0704-exploits/mybb-exec.txt

    MyBulletinBoard aka MyBB versions 1.2.3 and below remote code execution exploit.  Homepage: http://www.acid-root.new.fr/. Authored By DarkFig

  • http://packetstormsecurity.com/0405-exploits/waraxe-2004-SA031.txt

    e107 version 0.615 is vulnerable to full path disclosure, cross site scripting, remote file inclusion, and multiple SQL injection attacks.  Homepage: http://www.waraxe.us/. Authored By Janek Vind aka waraxe

  • http://packetstormsecurity.com/0404-exploits/Phorum347SQL.pl

    Remote exploit that makes use of a SQL injection vulnerability in Phorum version 3.4.7. Related advisory here.  Homepage: http://www.waraxe.us/. Authored By Janek Vind aka waraxe

  • http://packetstormsecurity.com/0603-exploits/waraxe-2006SA-047.txt

    It is possible to evade the SQL injection filters in PHPNuke 7.8.  Homepage: http://www.waraxe.us/. Authored By waraxe

  • http://packetstormsecurity.com/0705-exploits/waraxe-2007-SA051.txt

    2z project version 0.9.5 is susceptible to SQL injection attacks.  Homepage: http://www.waraxe.us/. Authored By waraxe

  • http://packetstormsecurity.com/0709-advisories/waraxe-2007-SA055.txt

    SiteX CMS version 0.7.3 Beta is susceptible to a SQL injection vulnerability.  Homepage: http://www.waraxe.us/. Authored By waraxe

  • http://packetstormsecurity.com/0709-advisories/waraxe-2007-SA056.txt

    NukeSentinel version 2.5.11 suffers from another critical SQL injection vulnerability.  Homepage: http://www.waraxe.us/. Authored By waraxe

  • Leave a Reply

    You must be logged in to post a comment.