This application requires Javascript for optimal performance.

MyBB.Birthdayprivacy.Privilege.Escalation

Release Date

Aug 04, 2009

Severity

medium

Impact

Privilege Escalation: Remote attackers can leverage their privilege on the vulnerable systems.

Description

This indicates an attack attempt against a Privilege Escalation vulnerability in MyBB.

The vulnerability is caused by an error when the vulnerable software incorrectly handles a "birthdayprivacy" parameter. It allows a remote attacker Privilege Escalation via sending a crafted web page.

Affected Products

MyBB prior to 1.4.7

Recommended Actions

Update to version 1.4.7 or apply patches.
http://www.mybboard.net/downloads

Coverage

IPS
VCM

Reference/s

http://secunia.com/advisories/35517/2/

Reference: VID-17551