In MyBB before 1.8.21, an attacker can abuse a default behavior of MySQL on many systems (that leads to truncation of strings that are too long for a database column) to create a PHP shell in the cache directory of a targeted forum via a crafted XML import, as demonstrated by truncation of aaaaaaaaaaaaaaaaaaaaaaaaaa.php.css to aaaaaaaaaaaaaaaaaaaaaaaaaa.php with a 30-character limit, aka theme import stylesheet name RCE.
References
Link | Resource |
---|---|
https://blog.mybb.com/2019/06/10/mybb-1-8-21-released-security-maintenance-release/ | Release Notes Vendor Advisory |
https://blog.ripstech.com/2019/mybb-stored-xss-to-rce/ | Exploit Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2019-06-15T17:05:08
Updated: 2019-06-15T17:05:08
Reserved: 2019-06-15T00:00:00
Link: CVE-2019-12831
JSON object: View
NVD Information
Status : Analyzed
Published: 2019-06-15T18:29:00.283
Modified: 2019-06-17T19:01:45.343
Link: CVE-2019-12831
JSON object: View
Redhat Information
No data.
CWE