PT-2014-2193 · Mybb · Advanced Forum Signatures

Publicado

2014-04-08

·

Atualizado

2017-08-29

·

CVE-2011-5277

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Advanced Forum Signatures plugin version 2.0.4 for MyBB
Description The issue concerns SQL injection vulnerabilities in the signature.php file of the Advanced Forum Signatures plugin for MyBB. Remote attackers can execute arbitrary SQL commands by manipulating certain parameters. The vulnerable parameters include afs type, afs background, afs showonline, afs bar left, afs bar center, afs full line1, afs full line2, afs full line3, afs full line4, afs full line5, and afs full line6.
Recommendations For Advanced Forum Signatures plugin version 2.0.4, consider restricting access to the signature.php file until a patch is available. As a temporary workaround, avoid using the vulnerable parameters in the plugin's configuration to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-5277

Produtos afetados

Advanced Forum Signatures