76295vdb entry
http://osvdb.org/76295 CVE-2011-5277
MyBB Advanced Forum Signatures - 'afsignatures-2.0.4' SQL Injection
Record summary
CVE-2011-5277 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Multiple SQL injection vulnerabilities in signature.php in the Advanced Forum Signatures (aka afsignatures) plugin 2.0.4 for MyBB allow remote attackers to execute arbitrary SQL commands via the (1) afs_type, (2) afs_background, (3) afs_showonline, (4) afs_bar_left, (5) afs_bar_center, (6) afs_full_line1, (7) afs_full_line2, (8) afs_full_line3, (9) afs_full_line4, (10) afs_full_line5, or (11) afs_full_line6 parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBMyBB Advanced Forum Signatures - 'afsignatures-2.0.4' SQL InjectionExploitDB exploitby Mario_VsNot analyzed1 file
References
646352Third-party advisory
http://secunia.com/advisories/46352 17961exploit
http://www.exploit-db.com/exploits/17961 50051vdb entry
http://www.securityfocus.com/bid/50051/info mybbafs-signature-sql-injection(70473)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/70473 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2011-5277