7.5
CVSSv2

CVE-2017-16780

Published: 10/11/2017 Updated: 03/10/2019
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The installer in MyBB prior to 1.8.13 allows remote malicious users to execute arbitrary code by writing to the configuration file.

Vulnerable Product Search on Vulmon Subscribe to Product

mybb mybb

Exploits

# Exploit Title: RCE in MyBB up to 1813 via installer # Date: Found on 05-29-2017 # Exploit Author: Pablo Sacristan # Vendor Homepage: mybbcom/ # Version: Version > 1813 (Fixed in 1813) # CVE : CVE-2017-16780 This RCE can be executed via CSRF but doesn't require it (in some special cases) The requirements are there shouldn't be ...