[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[KAPDA]MyBB 1.1.7~ htmlspeacialchar_uni(), fixjavascript(), functions_post.php ~[url]XSS attack


ORIGINAL ADVISORY:
http://myimei.com/security/2006-08-15/mybb-117-htmlspeacialchar_uni-fixjavascript-functions_postphp-urlxss-attack.html
http://kapda.ir/page-advisory.html

**************
??????-Summary?????-
Software: MyBB
Sowtware?s Web Site: http://www.mybboard.com
Versions: 1.1.7
Class: Remote
Status: Unpatched
Exploit: Available
Solution: Available
Discovered by: imei addmimistrator
Risk Level: low
??????Description?????
There is a security bug in MyBB 1.1.7 software (latest version fully patched) file functions_post.php that allows attacker performe an XSS attack.


FOR MORE DETAIL VISIT ORIGINAL ADVISORY


Mail converted by mhonarc 2.6.15
This archive provided courtesy of JSW4.NET, Internet Hosting Services for Small Business.