Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The domecode function in inc/functions_post.php in MyBulletinBoard (MyBB) 1.1.2, and possibly other versions, allows remote attackers to execute arbitrary PHP code via the username field, which is used in a preg_replace function call with a /e (executable) modifier.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
MyBB functions_post.php文件 domecode 任意代码执行漏洞
Vulnerability Description
MyBB是一款流行的Web论坛程序。 MyBB对注册用户名的处理存在问题,远程攻击者可能利用此漏洞在服务器上执行任意命令。 在注册的时候MyBB没有正确过滤对用户名字段的输入便在inc/functions_post.php文件domecode()函数的preg_replace调用中以"/e"修饰符使用了这些输入。攻击者可能以特制的用户名注册,然后预览包含有"/slap"字符串的贴子,导致执行任意PHP代码。
CVSS Information
N/A
Vulnerability Type
N/A