Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2008-0788
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2008-0788

Description:
Multiple cross-site request forgery (CSRF) vulnerabilities in MyBB 1.2.11 and earlier allow remote attackers to (1) hijack the authentication of moderators or administrators for requests that delete threads via a do_multideletethreads action to moderation.php and (2) hijack the authentication of arbitrary users for requests that delete private messages (PM) via a delete action to private.php.

CVE Status:
Candidate

References:

SREASON
  http://securityreason.com/securityalert/3656

SAID
  Secunia Advisory: SA28572

MISC
  http://community.mybboard.net/showthread.php?tid=27675

BUGTRAQ
  http://www.securityfocus.com/archive/1/486663


Return to the previous page.