Re: Mybb 1.6.8 'announcements.php' Sql Injection Vulnerabilitiy

看板Bugtraq作者時間13年前 (2012/06/27 02:01), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串4/5 (看更多)
On 22 June 2012 07:58, Henri Salo <henri@nerv.fi> wrote: >> ######################################################################################### >> # >> # Expl0iTs : >> # >> # [TarGeT]/Patch/announcements.php?aid=1[Sql] >> # >> # >> ######################################################################################### > > Could not reproduce. Could you give working PoC? > > - Henri Salo Agreed, untested but this looks sanitised well enough to me: Code from version 1.6.8 (and 1.6.7 / 1.6.6): http://www.mybb.com/download/latest $aid = intval($mybb->input['aid']); Can't see where in the page it's used unsanitised
文章代碼(AID): #1FwVZVFq (Bugtraq)
討論串 (同標題文章)
文章代碼(AID): #1FwVZVFq (Bugtraq)