PT-2008-2406 · Mybb · Mybb
Publicado
2008-02-15
·
Atualizado
2009-08-20
·
CVE-2008-0788
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
MyBB versions 1.2.11 and earlier
Description
The issue allows remote attackers to hijack the authentication of moderators, administrators, or arbitrary users. This can be done in two ways: (1) by deleting threads via a
do multideletethreads action to "moderation.php" and (2) by deleting private messages (PM) via a delete action to "private.php".Recommendations
For MyBB versions 1.2.11 and earlier, consider disabling the
do multideletethreads action in "moderation.php" and the delete action in "private.php" to prevent exploitation until a fix is available. Restrict access to "moderation.php" and "private.php" to minimize the risk of authentication hijacking.Exploit
Correção
CSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Mybb