lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <20060113113701.6175.qmail@securityfocus.com> Date: 13 Jan 2006 11:37:01 -0000 From: addmimistrator@...il.com To: bugtraq@...urityfocus.com Subject: MyBB 1.0.2 SQL injection Hey this is a bug report for mybb software ( forum software downloadable from http://www.mybboard.com) bug found by imei; bug is in usercp.php file line 830 (ver 1.0.2 latest ver) that allows SQL injection bug is in result of poor checking for $mybb->input['threadmode'] value that can have quote and can change other fields' values and may result to full access to admin cp (by injecting usergroup field) bug is reported to vendor and perhaps they will patched it soon. bests imei