Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

MyBB <= 1.8.31: Remote Code Execution Chain

Summary

A full exploit chain for MyBB <= 1.8.31: an SQL injection escalates to RCE when MyBB runs on PostgreSQL — pg_send_query allows stacked queries — with malicious templates executed by eval().
Published
Collected

original ↗

Related coverage

back