Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Tue, 8 May 2012 11:37:22 +0300
From: Henri Salo <henri@...v.fi>
To: oss-security@...ts.openwall.com
Subject: CVE-request: MyBB before 1.6.1

Can I get 2010 CVE-identifiers for these two vulnerabilities, thanks.

1. MyBB search.php keywords Parameter SQL Injection

MyBB contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the search.php script not properly sanitizing user-supplied input to the keywords parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data."""

Reference: http://osvdb.org/show/osvdb/70013
Advisory: http://yehg.net/lab/pr0js/advisories/%5Bmybb1.6%5D_sql_injection

2. MyBB private.php keywords Parameter SQL Injection

MyBB contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the private.php script not properly sanitizing user-supplied input to the keywords parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.

Reference: http://osvdb.org/show/osvdb/70014
Advisory: http://yehg.net/lab/pr0js/advisories/%5Bmybb1.6%5D_sql_injection

Both fixed in 1.6.1, same reporter but different php-file so do we want to merge these or should there be two CVEs? Please note that there is issue:

======================================================
Name: CVE-2010-4522
Status: Candidate
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4522
Phase: Assigned (20101209)
Category:
Reference: MLIST:[oss-security] 20101220 CVE Request: MyBB XSS bugs
Reference: URL:http://openwall.com/lists/oss-security/2010/12/20/1
Reference: MLIST:[oss-security] 20101221 Re: CVE Request: MyBB XSS bugs
Reference: URL:http://openwall.com/lists/oss-security/2010/12/22/2
Reference: CONFIRM:http://blog.mybb.com/2010/12/15/mybb-1-6-1-release-1-4-14-update/

Multiple cross-site scripting (XSS) vulnerabilities in MyBB (aka
MyBulletinBoard) 1.4.14, and 1.6.x before 1.6.1, allow remote
attackers to inject arbitrary web script or HTML via vectors related
to (1) editpost.php, (2) member.php, and (3) newreply.php.


Current Votes:
None (candidate not yet proposed)
======================================================

I do not understand why 1.6.1 release did not say anything about fixes to SQL-injection vulnerabilities.

- Henri Salo

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.