Release date:
Updated on:
Affected Systems:
MyBB 1.6.x
MyBB 1.4.x
Unaffected system:
MyBB 1.6.7
Description:
--------------------------------------------------------------------------------
Bugtraq id: 53417
MyBB is a popular Web forum program.
MySQL versions earlier than 1.6.7 have multiple security vulnerabilities, after successful exploitation, attackers can execute arbitrary script code, steal Cookie authentication creden。, control applications, access or modify data, or exploit other vulnerabilities in the underlying database to access sensitive data.
<* Source: Nathan Malcolm
Link: http://blog.mybb.com/2012/04/01/mybb-1-6-7-update-1-8-development/
Http://seclists.org/oss-sec/2012/q2/269
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
MyBB
----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.mybboard.com/