[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

MyBB <1.6.9 (editpost.php, posthash) SQL Injection Vulnerability

Author
Joshua Rogers
Risk
[
Security Risk High
]
0day-ID
0day-ID-20087
Category
web applications
Date add
31-12-2012
Platform
php
MyBB <1.6.9 is vulnerable to Stored, Error based, SQL Injection.
 
Vulnerable code:
 
/editpost.php
 
===
Line 398
===
$posthash_query = "posthash='{$posthash}' OR ";
===
 
 
It can be done by using Tamper Data(Or Live HTTP Headers), and when
submitting a post, edit the 'posthash' POST parameter to your payload,
submitting, then going to edit your post.
 
 
Small "HOWTO" in picture: http://imgur.com/a/JxfEI
 
This bug was not found by me, but afaik, I am the first one to release it.
 
 
-- 
*Joshua Rogers* - Retro Game Collector && IT Security Specialist

#  0day.today [2024-12-24]  #