MyBB <= 1.00 RC4 Multiple SQL Injection Vulnerabilities

high Nessus Plugin ID 19525

Synopsis

The remote web server hosts a PHP application that is affected by multiple SQL injection vulnerabilities.

Description

The version of MyBB installed on the remote host is affected by multiple SQL injection vulnerabilities :


- Multiple SQL injection vulnerabilities exist due to improper sanitization of user-supplied input passed via the 'Username' field, the 'action' parameter, and the 'polloptions' parameter. A remote attacker can exploit this issue to manipulate SQL queries, resulting in the disclosure of sensitive information and modification of data. (CVE-2005-2580)

- A SQL injection vulnerabilities exists due to improper sanitization of user-supplied input passed via the 'uid' parameter. A remote attacker can exploit this issue to manipulate SQL queries, resulting in the disclosure of sensitive information and modification of data.
(CVE-2005-2697)

- A SQL injection vulnerabilities exists due to improper sanitization of user-supplied input passed via the 'fid' parameter in the member.php script. A remote attacker can exploit this issue to manipulate SQL queries, resulting in the disclosure of sensitive information and modification of data. (CVE-2005-2778)

Note that the application is reportedly affected by several additional SQL injection vulnerabilities. However, Nessus has not tested for the additional vulnerabilities.

Solution

Apply the patch referenced in the vendor advisory. Alternatively, enable PHP's 'magic_quotes_gpc' setting.

See Also

https://www.securityfocus.com/archive/1/407960

https://www.securityfocus.com/archive/1/408624

https://www.securityfocus.com/archive/1/409523

https://community.mybb.com/showthread.php?tid=3350

Plugin Details

Severity: High

ID: 19525

File Name: mybb_fid_sql_injection.nasl

Version: 1.28

Type: remote

Family: CGI abuses

Published: 8/30/2005

Updated: 4/11/2022

Configuration: Enable thorough checks

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.6

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.2

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: cpe:/a:mybb:mybb

Required KB Items: www/PHP, installed_sw/MyBB

Exploit Available: true

Exploit Ease: No exploit is required

Patch Publication Date: 8/16/2005

Vulnerability Publication Date: 8/12/2005

Reference Information

CVE: CVE-2005-2580, CVE-2005-2697, CVE-2005-2778

BID: 14553, 14615, 14684