漏洞信息详情
MyBB inc/datahandlers/user.php birthdayprivacy参数SQL注入漏洞
漏洞简介
MyBB(又称MyBulletinBoard)1.4.7版本之前的版本的inc/datahandlers/user.php中存在SQL注入漏洞。远程认证用户可以借助birthdayprivacy参数,执行任意SQL指令。
漏洞公告
目前厂商还没有提供补丁或者升级程序,建议使用此软件的用户随时关注厂商的主页以获取最新版本:
MyBB MyBB 1.1
MyBB mybb_1407.zip
http://www.mybboard.net/download/latest
MyBB MyBB 1.1.3
MyBB mybb_1407.zip
http://www.mybboard.net/download/latest
MyBB MyBB 1.2
MyBB mybb_1407.zip
http://www.mybboard.net/download/latest
MyBB MyBB 1.2.1
MyBB mybb_1407.zip
http://www.mybboard.net/download/latest
MyBB MyBB 1.2.12
MyBB mybb_1407.zip
http://www.mybboard.net/download/latest
MyBB MyBB 1.2.14
MyBB mybb_1407.zip
http://www.mybboard.net/download/latest
MyBB MyBB 1.2.2
MyBB mybb_1407.zip
http://www.mybboard.net/download/latest
MyBB MyBB 1.4.2
MyBB mybb_1407.zip
http://www.mybboard.net/download/latest
MyBB MyBB 1.4.3
MyBB mybb_1407.zip
http://www.mybboard.net/download/latest
MyBB MyBB 1.4.5
MyBB mybb_1407.zip
http://www.mybboard.net/download/latest
MyBB MyBB 1.4.6
MyBB mybb_1407.zip
http://www.mybboard.net/download/latest
参考网址
来源: VUPEN
名称: ADV-2009-1653
链接:http://www.vupen.com/english/advisories/2009/1653
来源: BID
名称: 35458
链接:http://www.securityfocus.com/bid/35458
来源: mybboard.net
链接:http://mybboard.net/download/104
来源: blog.mybboard.net
链接:http://blog.mybboard.net/2009/06/15/mybb-147-released-security-update/
来源: MILW0RM
名称: 9001
链接:http://www.milw0rm.com/exploits/9001
来源: SECUNIA
名称: 35517
链接:http://secunia.com/advisories/35517
受影响实体
- Mybulletinboard Mybulletinboard:1.4.5<!--2000-1-1-->
- Mybulletinboard Mybulletinboard:1.4.6<!--2000-1-1-->
- Mybulletinboard Mybulletinboard:1.4.3<!--2000-1-1-->
- Mybulletinboard Mybulletinboard:1.4.2<!--2000-1-1-->
- Mybulletinboard Mybulletinboard:1.0.4<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...