Likes Likes:  0
Resultaten 1 tot 2 van de 2
Geen
  1. #1
    addmimistrator@gmail.com
    MyBB 1.0.2 SQL injection in usercp.php
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    MyBB 1.0.2 SQL injection in usercp.php

    this is a bug report for MyBB 1.0.2(latest version)
    bug found by imei
    there is a security bug in usercp.php line 830 that Allows SQL Injection and can result to full access to admin cp.
    bug is in result of poor checking of $mybb->input['threadmode'] value against all other values in usercp.php file line:830 ====>
    "threadmode" => $mybb->input['threadmode'],
    bug reported to vendors some days ago
    bests.
    imei

  2. #2
    o.y.6@hotmail.com
    MyBB 1.0.2 SQL injection in usercp.php
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: MyBB 1.0.2 SQL injection in usercp.php

    Hiz .. look at phpMyAdmin or you database

    threadmode << After >> usergroup .. then you can't edit usergroup to get super acsses to any user you wn't

    UPDATE Query :-

    ','','','')/* Only You CAn Edit

    showsigs showavatars showquickreply ppp tpp daysprune dateformat timeformat timezone dst buddylist ignorelist style away awaydate returndate awayreason pmfolders notepad rating referrer reputation
    regip language timeonline showcodebuttons

    //* Do You Have Any Idea For That ? *//

Webhostingtalk.nl

Contact

  • Rokin 113-115
  • 1012 KP, Amsterdam
  • Nederland
  • Contact
© Copyright 2001-2026 Webhostingtalk.nl.
Web Statistics