——————-Summary—————-
Software: MyBB
Sowtware’s Web Site: http://www.mybboard.com
Versions: 1.1.7
Class: Remote
Status: Unpatched
Exploit: Available
Solution: Available
Discovered by: imei addmimistrator
Risk Level: low
—————–Description—————
There is a security bug in MyBB 1.1.7 software (latest version fully patched) file functions_post.php that allows attacker performe an XSS attack.
Bug is in result of poor regullar expression for url patterns, also allowing unicode entries to bypass fixjavascript()’s checks and fixes… Cause of this bug, attacker may post some contents in URL tag, that evaluate as a correct URL instead of a javascript call and in case of clicking user, an arbitarry script may execute.
————–Exploit———————-
[url]java& 115;cript://%0a%0dalert(1);[/url]
————–Solution———————
upgrade to vendors provided patch
————–Credit———————–
Discovered by: imei addmimistrator
addmimistrator(4}gmail(O}com
www.myimei.com
[…] ORIGINAL ADVISORY: http://myimei.com/security/2006-08-15/mybb-117-htmlspeacialchar_uni-fixjavascript-functions_postphp-urlxss-attack.html http://kapda.ir/page-advisory.html […]
Left by NTEK Technologies » Blog Archive » [KAPDA]MyBB 1.1.7~ htmlspeacialchar_uni(), fixjavascript(), on September 15th, 2006