Affected Versions:
MyBB 1.4.10 vulnerability description:
MyBB is a popular Web forum program.
If you set the action to donate, MyBB's MYPS plug-in does not properly filter and submit it to myps. the username parameter of the php page is returned to the user. Remote attackers can execute cross-site scripting attacks by submitting malicious requests, resulting in arbitrary HTML and script code execution in users' browser sessions.
<* Reference
Steven Abbagnaro (Steve@ProminentSecurity.com)
Http://secunia.com/advisories/37910/
*>
Test method:
The Program (method) provided on this site may be offensive and only used for security research and teaching. You are at your own risk! Http: // server/myps. php? Action = donate & username = "/>
Http: // server/myps. php? Action = donate & username = ">
Http: // server/myps. php? Action = donate & username =
Security suggestions:
Vendor patch:
MyBB
----
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.mybboard.com/