MyBB 1.0.2~search.php~XSS Attack
Posted by imei on January 25th, 2006——————–Summary—————-
Software: MyBB
Sowtware’s Web Site: http://www.mybboard.com
Versions: 1.0.2 updated
Class: Remote
Status: Unpatched
Exploit: Available
Solution: Not Available
Discovered by: imei addmimistrator
Risk Level:low
—————–Description—————
Mybb has a security bug that allows hackers run unwanted scripts into client’s browser that well known as XSS cross site scripting attack.
bug is in result of poor cheknig of two input varibles “sortby” & “sortordr” in redirection page of […]