MyBB < 1.8.11 Multiple Vulnerabilities
High Nessus Network Monitor Plugin ID 700070
SynopsisThe remote web server is running a PHP application that is vulnerable to multiple vulnerabilities.
DescriptionVersions of MyBB (MyBulletinBoard) prior to 1.8.11 are affected by the following vulnerabilities :
- The file 'usercp.php' contains an error that can allow server side request forgery (SSRF) via specially-crafted requests. (CVE-2017-7566)
- An unspecified user-input error can allow cross-site scripting attacks (XSS). (CVE-2017-8103)
- The file 'upload/admin/modules/config/smilies.php' contains a user-input validation error that can allow file disclosure via path traversal. (CVE-2017-8104)
SolutionUpgrade to MyBB version 1.8.11 or later.