PT-2014-2193 · Mybb · Advanced Forum Signatures
Publicado
2014-04-08
·
Atualizado
2017-08-29
·
CVE-2011-5277
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Advanced Forum Signatures plugin version 2.0.4 for MyBB
Description
The issue concerns SQL injection vulnerabilities in the signature.php file of the Advanced Forum Signatures plugin for MyBB. Remote attackers can execute arbitrary SQL commands by manipulating certain parameters. The vulnerable parameters include
afs type, afs background, afs showonline, afs bar left, afs bar center, afs full line1, afs full line2, afs full line3, afs full line4, afs full line5, and afs full line6.Recommendations
For Advanced Forum Signatures plugin version 2.0.4, consider restricting access to the signature.php file until a patch is available. As a temporary workaround, avoid using the vulnerable parameters in the plugin's configuration to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
SQL injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Advanced Forum Signatures