Vulnerabilities
Vulnerable Software
Mybb:  >> Mybb  >> 1.4.3  Security Vulnerabilities
MyBB (aka MyBulletinBoard) before 1.4.12 does not properly restrict uid values for group join requests, which allows remote attackers to cause a denial of service (resource consumption) by using guest access to submit join request forms for moderated groups, related to usercp.php and managegroup.php.
CVSS Score
5.0
EPSS Score
0.012
Published
2010-12-30
MyBB (aka MyBulletinBoard) 1.4.3 includes the sensitive my_post_key parameter in URLs to moderation.php with the (1) mergeposts, (2) split, and (3) deleteposts actions, which allows remote attackers to steal the token and bypass the cross-site request forgery (CSRF) protection mechanism to hijack the authentication of moderators by reading the token from the HTTP Referer header.
CVSS Score
6.8
EPSS Score
0.001
Published
2009-08-25
SQL injection vulnerability in pages.php in Custom Pages 1.0 plugin for MyBulletinBoard (MyBB) allows remote attackers to execute arbitrary SQL commands via the page parameter.
CVSS Score
7.5
EPSS Score
0.001
Published
2009-02-20


Contact Us

Shodan ® - All rights reserved