Home page logo

bugtraq logo Bugtraq mailing list archives

[KAPDA::#53] MYBB XSS and Dir Traversal in usercp.php
From: roozbeh_afrasiabi () yahoo com
Date: 29 Jul 2006 06:41:46 -0000

Vulnerable products : MYBB 1.x
Vendor: http://www.mybboard.net
Risk: Low
Vulnerabilities: MYBB XSS and Dir Traversal in usercp.php 

Date :
Found : Feb 22 2006
Vendor Contacted : N/A
Release Date : N/A

About :
MyBB is a powerful, efficient and free forum package developed in PHP and MySQL.MyBB has been designed with the end 
users in mind, you and your subscribers. Full control over your discussion system is p resented right at the tip of 
your fingers, from multiple styles and themes to the ultimate customisation of your forums using the template system.

Cross_Site_Scripting (XSS,CSS):

MYBB is affected by a cross-site scripting vulnerability. This issue is due to the failure of the application to 
properly sanitize user-
supplied input.

As a result of this vulnerability, it is possible for a remote attacker to create a malicious link containing script 
code that will be executed
in the browser of an unsuspecting user when followed.

Detail and PoC :


The application does not validate the "gallery" variable upon submission to the usercp.php script. 


Dir Traversal For images:


Solution :

Credit :
Discoverd by : Roozbeh Afrasiabi

POC by : imei addmimistrator


  By Date           By Thread  

Current thread:
  • [KAPDA::#53] MYBB XSS and Dir Traversal in usercp.php roozbeh_afrasiabi (Jul 29)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]