diff options
author | joneum <joneum@FreeBSD.org> | 2018-03-24 16:46:25 +0800 |
---|---|---|
committer | joneum <joneum@FreeBSD.org> | 2018-03-24 16:46:25 +0800 |
commit | 9a39808c60c7d2e9d085e832452614596d5320f3 (patch) | |
tree | 64f3f1e4f2126296c94b577fdba6ca267aa8c0c7 /security | |
parent | 538873c14a7022a7cc26d93225a16e85ddc1bf69 (diff) | |
download | freebsd-ports-gnome-9a39808c60c7d2e9d085e832452614596d5320f3.tar.gz freebsd-ports-gnome-9a39808c60c7d2e9d085e832452614596d5320f3.tar.zst freebsd-ports-gnome-9a39808c60c7d2e9d085e832452614596d5320f3.zip |
Document vulnerability in www/mybb
Diffstat (limited to 'security')
-rw-r--r-- | security/vuxml/vuln.xml | 34 |
1 files changed, 34 insertions, 0 deletions
diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index 60af444ab07b..8dc5afd52e6b 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -58,6 +58,40 @@ Notes: * Do not forget port variants (linux-f10-libxml2, libxml2, etc.) --> <vuxml xmlns="http://www.vuxml.org/apps/vuxml-1"> + <vuln vid="d50a50a2-2f3e-11e8-86f8-00e04c1ea73d"> + <topic>mybb -- multiple vulnerabilities</topic> + <affects> + <package> + <name>mybb</name> + <range><lt>1.8.15</lt></range> + </package> + </affects> + <description> + <body xmlns="http://www.w3.org/1999/xhtml"> + <p>mybb Team reports:</p> + <blockquote cite="https://blog.mybb.com/2018/03/15/mybb-1-8-15-released-security-maintenance-release/"> + <p>Medium risk: Tasks Local File Inclusion</p> + <p>Medium risk: Forum Password Check Bypass</p> + <p>Low risk: Admin Permissions Group Title XSS</p> + <p>Low risk: Attachment types file extension XSS</p> + <p>Low risk: Moderator Tools XSS</p> + <p>Low risk: Security Questions XSS</p> + <p>Low risk: Settings Management XSS</p> + <p>Low risk: Templates Set Name XSS</p> + <p>Low risk: Usergroup Promotions XSS</p> + <p>Low risk: Warning Types XSS</p> + </blockquote> + </body> + </description> + <references> + <url>https://blog.mybb.com/2018/03/15/mybb-1-8-15-released-security-maintenance-release/</url> + </references> + <dates> + <discovery>2018-03-15</discovery> + <entry>2018-03-24</entry> + </dates> + </vuln> + <vuln vid="6d52bda1-2e54-11e8-a68f-485b3931c969"> <topic>SQLite -- Corrupt DB can cause a NULL pointer dereference</topic> <affects> |