7.5
CVSSv2

CVE-2008-0382

Published: 22/01/2008 Updated: 15/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 760
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple eval injection vulnerabilities in MyBB 1.2.10 and previous versions allow remote malicious users to execute arbitrary code via the sortby parameter to (1) forumdisplay.php or (2) a results action in search.php.

Vulnerable Product Search on Vulmon Subscribe to Product

mybulletinboard mybulletinboard 1.0

mybulletinboard mybulletinboard 1.0.1

mybulletinboard mybulletinboard 1.1.3

mybulletinboard mybulletinboard 1.1.4

mybulletinboard mybulletinboard 1.2.3

mybulletinboard mybulletinboard 1.2.5

mybulletinboard mybulletinboard 1.0.2

mybulletinboard mybulletinboard 1.0.3

mybulletinboard mybulletinboard 1.1.5

mybulletinboard mybulletinboard 1.1.7

mybulletinboard mybulletinboard 1.0.4

mybulletinboard mybulletinboard 1.0_pr2

mybulletinboard mybulletinboard 1.1

mybulletinboard mybulletinboard 1.1.8

mybulletinboard mybulletinboard 1.10

mybulletinboard mybulletinboard 1.1.1

mybulletinboard mybulletinboard 1.1.2

mybulletinboard mybulletinboard 1.2

mybulletinboard mybulletinboard 1.2.10

Exploits

#!/usr/bin/php -q -d short_open_tag=on <?php // magic_quotes_gpc needs to be off error_reporting(0); ini_set("max_execution_time",0); ini_set("default_socket_timeout",5); if ($argc<5) { print "-------------------------------------------------------------------------\r\n"; print " MyBB <= 1210 Remote Code Execution Expl ...
[waraxe-2008-SA#061] - Remote Code Execution in MyBB 1210 =============================================================================== Author: Janek Vind "waraxe" Independent discovery: koziolek Date: 16 January 2008 Location: Estonia, Tartu Web: wwwwaraxeus/advisory-61html Target software description: ~~~~~~~~~~~~~~~~~~~~~~~~~~~ ...