Title: ====== My Little Forum 2.3.7 - Multiple Vulnerability Product & Service Introduction: =============================== My little forum is a simple PHP and MySQL based internet forum that displays the messages in classical threaded view (tree structure). It is Open Source licensed under the GNU General Public License. The main claim of this web forum is simplicity. Furthermore it should be easy to install and run on a standard server configuration with PHP and MySQL. Software Link: ============== https://github.com/ilosuna/mylittleforum/archive/master.zip Vulnerability Type: ========================= Cross-Site Request Forgery Stored Cross-Site Scripting CSRF Allow To Backup Disclosure Vulnerability Details: ============================== This WebApplication is vulnerable and suffer from some vulnerablity. Severity Level: =============== High Proof of Concept (PoC): ======================= 1. CSRF (Add Page) With this exploit can add page in webapp.
2. Stored XSS:
3. Backup Disclosure: with this exploit we can delect htaccess in backup folder for access to backups.
Next use exploit go to: http://localhost/mylittleforum-master/backup/ Author: ================== Ashiyane Digital Security Team ======================= Title: ====== My Little Forum 2.3.7 (Installer) - Cross-Site Scripting Product & Service Introduction: =============================== My little forum is a simple PHP and MySQL based internet forum that displays the messages in classical threaded view (tree structure). It is Open Source licensed under the GNU General Public License. The main claim of this web forum is simplicity. Furthermore it should be easy to install and run on a standard server configuration with PHP and MySQL. Software Link: ============== https://github.com/ilosuna/mylittleforum/archive/master.zip Vulnerability Type: ========================= Cross-Site Scripting Vulnerability Details: ============================== Installer of My Little Forum is vulnerable to cross-site scripting. Proof of Concept (PoC): =======================
Author: ================== Ashiyane Digital Security Team ||