MyBB 1.1.7 ~ admin/global.php ~ XSS Attack
Posted by imei on August 17th, 2006——————-Summary—————-
Software: MyBB
Sowtware’s Web Site: http://www.mybboard.com
Versions: 1.1.7
Class: Remote
Status: Unpatched
Exploit: Available
Solution: Available
Discovered by: imei addmimistrator
Risk Level: Medium
—————–Description—————
There is some security bug in MyBB 1.1.7 software (latest version fully patched) file admin/global.php that allows attacker performe an XSS attack.
Bug is in result of trust to variable $_SERVER[PHP_SELF] that may dont point to script that is executing and […]