MyBB global.php and init.php data manipulation

mybb-global-init-data-manipulation (25865) The risk level is classified as MediumMedium Risk

Description:

MyBB could allow a remote attacker to manipulate arbitrary script variables. A remote attacker could access the global.php and inc/init.php scripts and manipulate arbitrary script variables or execute arbitrary HTML and script code in the context of the hosted site.


Consequences:

Data Manipulation

Remedy:

Upgrade to the latest version of MyBB (1.1.1 or later), available from the MyBB Web site. See References.

References:

  • BugTraq Mailing List, Fri Apr 14 2006 - 23:57:56 CDT: [KAPDA]MyBB1.1.0~global.php~ParameterExtracting.
  • MyBB Web site: MyBB Website.
  • BID-17564: MyBB Global Variable Overwrite Vulnerability
  • CVE-2006-1912: MyBB (MyBulletinBoard) 1.1.0 does not set the constant KILL_GLOBAL variable in (1) global.php and (2) inc/init.php, which allows remote attackers to initialize arbitrary variables that are processed by an @extract command, which could then be leveraged to conduct cross-site scripting (XSS) or SQL injection attacks.
  • OSVDB ID: 24710: MyBulletinBoard (MyBB) global.php Variable Overwrite
  • OSVDB ID: 24711: MyBulletinBoard (MyBB) inc/init.php Variable Overwrite
  • SA19668: MyBB Cross-Site Scripting and Variable Manipulation Vulnerabilities
  • VUPEN/ADV-2006-1381: MyBB Multiple Remote SQL Injection and Cross Site Scripting Vulnerabilities

Platforms Affected:

  • MyBB MyBB 1.1

Reported:

Apr 14, 2006

The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

For corrections or additions please email xforce@iss.net

Return to the main page