MyBB 1.6.x < 1.6.11 Multiple Vulnerabilities
High Nessus Network Monitor Plugin ID 8613
SynopsisThe remote web server is running a PHP application that is vulnerable to multiple attack vectors.
DescriptionThe remote web server hosts MyBulletinBoard, a web-based discussion board application. Versions of MyBB 1.6.x prior to 1.6.11 are potentially affected by multiple issues :
- A security bypass vulnerability exists due to improper validation of the username during registration. This issue only affects installs using a MySQL database.
- A flaw exists in which accounts without login keys can be hijacked.
- The 'generate_post_check()' function in the 'functions.php' scripts contains an unspecified weakness.
- A flaw exists that could make anonymous statistics not always be anonymous.
- An information disclosure vulnerability exists related to the database backups being exposed in logs.
SolutionUpgrade to MyBB 1.6.11 or later.