CVE-2017-16780
CRITICALMyBB < 1.8.12 - Remote Code Execution via Installer Configuration File Write
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-16780. PoCs published by Pabstersac.
AI-analyzed exploit summary This exploit leverages a CSRF vulnerability in MyBB's installer to inject arbitrary PHP code into the /inc/config.php file by manipulating the SQLite database path parameter. The lack of input sanitization allows for remote code execution when an admin visits a crafted page.
Description
The installer in MyBB before 1.8.13 allows remote attackers to execute arbitrary code by writing to the configuration file.
Exploits (1)
This exploit leverages a CSRF vulnerability in MyBB's installer to inject arbitrary PHP code into the /inc/config.php file by manipulating the SQLite database path parameter. The lack of input sanitization allows for remote code execution when an admin visits a crafted page.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H