New User, Welcome!     Login

bulletin boards

Web Wiz Forums Directory traversal

####################
- Description:
####################
Web Wiz Forums bulletin board system is the ideal forum package for  
your website's community.

####################
- Vulnerability:
####################

GR Board v1.8.6. (theme) Local File Inclusion Vulnerability

=====================================================================

Description:

GRBoard (VERSION 1.8 )is bulletin board system of Korea.
It is freely available for all platforms that supports PHP and MySQL.
But I find Remote File Inclusion vulnerability.

=====================================================================


[waraxe-2008-SA#064] - Sql Injection in MyBB 1.2.11

Target software description:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

MyBB is a discussion board that has been around for a while; it has evolved
from other bulletin boards into the forum package it is today. Therefore,
it is a professional and efficient discussion board, developed by an active
team of developers.

Vulnerabilities discovered
===============================================================================

Advisory 02/2010: MyBB Password Reset Weak Random Numbers Vulnerability

Overview:

  Quote from http://www.mybboard.net
  "MyBB is a discussion board that has been around for a while; it has
   evolved from other bulletin boards into the forum package it is
   today. Therefore, it is a professional and efficient discussion
   board, developed by an active team of developers. The MyBB history
   has been recorded and is available for the interested to read.
   You can also read more about the MyBB team and why they develop
   MyBB in their spare time. We also like to highlight the most

GR Board v1.8.6.1 stab (page.php?theme) Remote File Inclusion Vulnerability

=====================================================================

Description:

GRBoard (VERSION 1.8 )is bulletin board system of Korea.
It is freely available for all platforms that supports PHP and MySQL.
But I find Remote File Inclusion vulnerability.

=====================================================================


[waraxe-2008-SA#061] - Remote Code Execution in MyBB 1.2.10

Target software description:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

MyBB is a discussion board that has been around for a while; it has evolved
from other bulletin boards into the forum package it is today. Therefore,
it is a professional and efficient discussion board, developed by an active
team of developers.

Vulnerabilities discovered
===============================================================================

[waraxe-2008-SA#062] - Multiple Sql Injections in MyBB 1.2.10

Target software description:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

MyBB is a discussion board that has been around for a while; it has evolved
from other bulletin boards into the forum package it is today. Therefore,
it is a professional and efficient discussion board, developed by an active
team of developers.

Vulnerabilities discovered
===============================================================================

Advisory 01/2010: MyBB Password Reset Email BCC: Injection Vulnerability

Overview:

  Quote from http://www.mybboard.net
  "MyBB is a discussion board that has been around for a while; it has
   evolved from other bulletin boards into the forum package it is
   today. Therefore, it is a professional and efficient discussion
   board, developed by an active team of developers. The MyBB history
   has been recorded and is available for the interested to read.
   You can also read more about the MyBB team and why they develop
   MyBB in their spare time. We also like to highlight the most

Hijacking Safari 4 Top Sites with Phish Bombs

A real-world hacking scenario would look like:

1. Attacker injects malicious javascript on 
    (a) His or her evil site OR
    (b) On a legitimate site which allows javascript (e.g. bulletin boards,
dashboards, etc).

2. Victim visits the above site.

3. Malicious javascript runs and first checks browser history (using CSS



Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!