Release date:
Updated on:
Affected Systems:
MyBB Facebook profile link on Postbit
Description:
--------------------------------------------------------------------------------
Bugtraq id: 56943
Facebook profile link on Postbit can add Facebook buttons to user posts and call their links.
MyBB Facebook profile link on Postbit plug-in 2.4 and other versions do not validate the input of the 'Facebook id/nickname' field. You can create special requests and execute arbitrary script code in the browser.
<* Source: limb0
Link: http://secunia.com/advisories/51554/
Http://osvdb.org/88418
Http://www.exploit-db.com/exploits/23355/
Http://packetstormsecurity.org/files/118828/MyBB-Facebook-Profile-2.4-Cross-Site-Scripting.html
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
MyBB
----
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://mods.mybb.com/view/facebook-profile-link-on-postbit-2-2