Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

MyBB 1.6.x < 1.6.11 Multiple Vulnerabilities

High

Synopsis

The remote web server is running a PHP application that is vulnerable to multiple attack vectors.

Description

The remote web server hosts MyBulletinBoard, a web-based discussion board application. Versions of MyBB 1.6.x prior to 1.6.11 are potentially affected by multiple issues :

- A security bypass vulnerability exists due to improper validation of the username during registration. This issue only affects installs using a MySQL database.

- A flaw exists in which accounts without login keys can be hijacked.

- The 'generate_post_check()' function in the 'functions.php' scripts contains an unspecified weakness.

- A flaw exists that could make anonymous statistics not always be anonymous.

- An information disclosure vulnerability exists related to the database backups being exposed in logs.

Solution

Upgrade to MyBB 1.6.11 or later.