Local File Inclusion and reading password-protected forums in MyBB
Recently, I've been looking at the MyBB forum software to try to find security issues with it. Here are the results that I have so far. These have been reported privately to the maintainers of the software. The first two are fixed in version 1.8.15, and the third will be fixed in 1.8.16.
Tools and Maintenance -> Task Manager -> Add New Task
Then, when submitting the request, modify the "file" POST parameter as shown below, and the file "../../../file.php" will be executed when the task is run (if the file exists).

However, MyBB does not require a password for users to subscribe to a password-protected forum (or the threads inside it). Furthermore, when users subscribe to a forum, they can get a notification by email or private message every time a user posts. This notification contains an excerpt of the message which was posted in the private forum.
To use, simply access the below URL while logged in as an ordinary user, then follow the prompts:
http://<target website>/usercp2.php?action=addsubscription&type=forum&fid=<forum id>&my_post_key=<your post key>
1. Local File Inclusion in admin panel.
From the admin panel, select:Tools and Maintenance -> Task Manager -> Add New Task
Then, when submitting the request, modify the "file" POST parameter as shown below, and the file "../../../file.php" will be executed when the task is run (if the file exists).

2. Read posts in password-protected forums
A feature of MyBB is the ability to create password-protected forums. If a forum is password-protected, then only users who know the password will be able to view the posts in that forum.However, MyBB does not require a password for users to subscribe to a password-protected forum (or the threads inside it). Furthermore, when users subscribe to a forum, they can get a notification by email or private message every time a user posts. This notification contains an excerpt of the message which was posted in the private forum.
To use, simply access the below URL while logged in as an ordinary user, then follow the prompts:
http://<target website>/usercp2.php?action=addsubscription&type=forum&fid=<forum id>&my_post_key=<your post key>
I really loved reading your blog. It was very well authored and easy to understand. Unlike other blogs I have read which are really not that good.Thanks alot
ReplyDeletejogos friv gratis
Jogos online
jogos 4 school
Planning a wedding that takes place under one roof, offers so many advantages. In the first instance a venue that offers a wedding package, tend to employ people who are experts in this field. They plan weddings for a living. They are the experts. Whilst many venues only offer the room and catering, a wedding under one roof many include a wedding planner and if they don't they will be working regularly with florists, cake makers, companies that do decorations, DJ's and photographers.
ReplyDeleteJogo para menino
360 jogos 2019
game io 2019
The cultural history of Inter-war Europe is filled with such powerful and influential interpretations of a reality that defeats the human capacity to imagine evil. Take Picasso's Guernica for instance. In June 1937, Picasso finished painting the Modernist classic in response to another April tragedy: the bombing of the Spanish city of Guernica during the civil war. It was his anguished creativity reacting to George Steer's eyewitness account of the incident.
ReplyDeletekizi kizi 2 games
free games
friv Games for kids 2019
Amazing information, thank you for your ideas. After a long time, I have studied an interesting article.
ReplyDeleteMobile Testing Training in Chennai
mobile automation testing training in chennai
Mobile Testing Training in OMR
Manual Testing Training in Chennai
Manual Testing Training institute in Chennai
Drupal Training in Chennai
Photoshop Course in Chennai
Awesome blog with great piece of information. Very well written blog with crisp and neat content. Keep sharing more such blogs.
ReplyDeleteCloud Computing Training in Chennai
Cloud Training in Chennai
Data Science Course in Chennai
Azure courses in Chennai
VMware course
R Programming Training in Chennai
Cloud Certification in Chennai
The way you have presented the blog is really good.... thanks for sharing with us...
ReplyDeleteAndroid Training in Chennai
Android Course in Chennai
android development course in chennai
Android training
Android Training in Annanagar
Android training in vadapalani
Digital Marketing Course in Chennai
Python Training in Chennai
Big data training in chennai
JAVA Training in Chennai
nice explanation, thanks for sharing, it is very informative
ReplyDeletetop 100 machine learning interview questions
top 100 machine learning interview questions and answers
Machine learning interview questions
Machine learning job interview questions
Machine learning interview questions techtutorial
Machine learning job interview questions and answers
Machine learning interview questions and answers online
Machine learning interview questions and answers for freshers
interview question for machine learning
machine learning interview questions and answers
Looking for best English to Tamil Translation tool online, make use of our site to enjoy Tamil typing and directly share on your social media handle. mallika manivannan novels
ReplyDeleteThank you for this informative blog
ReplyDeleteTop 5 Data science training in chennai
Data science training in chennai
Data science training in velachery
Data science training in OMR
Best Data science training in chennai
Data science training course content
Data science syllabus
Data science courses in chennai
Data science training Institute in chennai
Data science online course
Thanks for sharing an informative blog keep rocking bring more details.I like the helpful info you provide in your articles. I’ll bookmark your weblog and check again here regularly. I am quite sure I will learn much new stuff right here! Good luck for the next!
ReplyDeletemobile application development training online
mobile app development course
mobile application development training
mobile app development course online
mobile application development course
online mobile application development
learn mobile application development
Really appreciate for providing the valuable post and It was very helpful for my future. Thank you & Keep it up!!!
ReplyDeleteOracle Training in Chennai
best oracle training institute in chennai
Unix Training in Chennai
Power BI Training in Chennai
Tableau Training in Chennai
Oracle DBA Training in Chennai
Excel Training in Chennai
Linux Training in Chennai
Oracle Training in OMR
Oracle Training in Adyar
Awesome Blog...waiting for next update...
ReplyDeletecore java training in chennai
core java training
core java course
core java training in T nagar
core java training in Guindy
C C++ Training in Chennai
javascript training in chennai
Hibernate Training in Chennai
LoadRunner Training in Chennai
Mobile Testing Training in Chennai
Good Blog!!! The way you have conveyed your blog is more impressive...
ReplyDeleteJAVA Training in Chennai
java class
best java coaching center in chennai
Java training institute in chennai
java training in Guindy
JAVA Training in Tambaram
Python Training in Chennai
Big data training in chennai
SEO training in chennai
Selenium Training in Chennai
Nice post......thanks for sharing useful information.
ReplyDeletePython training in Chennai/
Python training in OMR/
Python training in Velachery/
Python certification training in Chennai/
Python training fees in Chennai/
Python training with placement in Chennai/
Python training in Chennai with Placement/
Python course in Chennai/
Python Certification course in Chennai/
Python online training in Chennai/
Python training in Chennai Quora/
Best Python Training in Chennai/
Best Python training in OMR/
Best Python training in Velachery/
Best Python course in Chennai/
Wonderful Blog.... Thanks for sharing with us...
ReplyDeleteHadoop Training in Chennai
Big data training in chennai
Big Data Training
bigdata and hadoop training in chennai
Hadoop Training in Velachery
Big data training in Adyar
Python Training in Chennai
Software testing training in chennai
JAVA Training in Chennai
Selenium Training in Chennai
Thanks for sharing informative article with us..
ReplyDeleteDOT NET Training in Chennai
DOT NET Training Chennai
dot net course fees in chennai
.net training
dot net training in Velachery
Html5 Training in Chennai
Spring Training in Chennai
Struts Training in Chennai
Wordpress Training in Chennai
SAS Training in Chennai
Fantastic blog!!! Thanks for sharing with us, Waiting for your upcoming data.
ReplyDeleteDigital Marketing Course in Chennai
Digital Marketing Course
digital marketing classes in chennai
Digital Marketing Training in Chennai
Digital marketing course in Guindy
Digital marketing course in Tambaram
Python Training in Chennai
Big data training in chennai
SEO training in chennai
JAVA Training in Chennai
I believe that your blog would help the readers by giving them a useful information. Waiting for more updates from this admin.
ReplyDeleteSpoken English Classes in Coimbatore
Best Spoken English Classes in Coimbatore
Spoken English Class in Coimbatore
Spoken English in Coimbatore
Spoken English Classes in Chennai
IELTS Coaching in Chennai
English Speaking Classes in Mumbai
IELTS Classes in Mumbai
Spoken English Class in Anna Nagar
IELTS Coaching in Tambaram
x-cart integration
ReplyDeleteThis is the first & best article to make me satisfied by presenting good content. I feel so happy and delighted. Thank you so much for this article.
ReplyDeleteLearn Best Digital Marketing Course in Chennai
Digital Marketing Course Training with Placement in Chennai
Best Big Data Course Training with Placement in Chennai
Big Data Analytics and Hadoop Course Training in Chennai
Best Data Science Course Training with Placement in Chennai
Data Science Online Certification Course Training in Chennai
Learn Best Android Development Course Training Institute in Chennai
Android Application Development Programming Course Training in Chennai
Learn Best AngularJS 4 Course Online Training and Placement Institute in Chennai
Learn Digital Marketing Course Training in Chennai
Digital Marketing Training with Placement Institute in Chennai
Learn Seo Course Training Institute in Chennai
Learn Social Media Marketing Training with Placement Institute in Chennai
Thanks for sharing valuable information.
ReplyDeletedigital marketing training
digital marketing in Chennai
digital marketing training in Chennai
digital marketing course in Chennai
digital marketing course training in omr
digital marketing certification
digital marketing course training in velachery
digital marketing training and placement
digital marketing courses with placement
digital marketing course with job placement
digital marketing institute in Chennai
digital marketing certification course in Chennai
digital marketing course training in Chennai
Digital Marketing course in Chennai with placement
Aluminium Composite Panel or ACP Sheet is used for building exteriors, interior applications, and signage. They are durable, easy to maintain & cost-effective with different colour variants.
ReplyDeleteSoma pill is very effective as a painkiller that helps us to get effective relief from pain. This cannot cure pain. Yet when it is taken with proper rest, it can offer you effective relief from pain.
ReplyDeleteThis painkiller can offer you relief from any kind of pain. But Soma 350 mg is best in treating acute pain. Acute pain is a type of short-term pain which is sharp in nature. Buy Soma 350 mg online to get relief from your acute pain.
https://globalonlinepills.com/product/soma-350-mg/
Buy Soma 350 mg
Soma Pill
Buy Soma 350 mg online
Buy Soma 350 mg online
Soma Pill
Buy Soma 350 mg
Really nice post. Thank you for sharing amazing information.
ReplyDeletePython training in Chennai/Python training in OMR/Python training in Velachery/Python certification training in Chennai/Python training fees in Chennai/Python training with placement in Chennai/Python training in Chennai with Placement/Python course in Chennai/Python Certification course in Chennai/Python online training in Chennai/Python training in Chennai Quora/Best Python Training in Chennai/Best Python training in OMR/Best Python training in Velachery/Best Python course in Chennai
Nice post Haroon Ullah
ReplyDeleteThe article is so informative. This is more helpful for our
ReplyDeletebest software testing training in chennai
best software testing training institute in chennai with placement
software testing training
courses
software testing training and placement
software testing training online
software testing class
software testing classes in chennai
best software testing courses in chennai
automation testing courses in chennai
Thanks for sharing.
This is the first & best article to make me satisfied by presenting good content. I feel so happy and delighted. Thank you so much for this article.
ReplyDeleteLearn Best Digital Marketing Course in Chennai
Digital Marketing Course Training with Placement in Chennai
Best Big Data Course Training with Placement in Chennai
Big Data Analytics and Hadoop Course Training in Chennai
Best Data Science Course Training with Placement in Chennai
Data Science Online Certification Course Training in Chennai
Learn Best Android Development Course Training Institute in Chennai
Android Application Development Programming Course Training in Chennai
Learn Best AngularJS 4 Course Online Training and Placement Institute in Chennai
Learn Digital Marketing Course Training in Chennai
Digital Marketing Training with Placement Institute in Chennai
Learn Seo Course Training Institute in Chennai
Learn Social Media Marketing Training with Placement Institute in Chennai
I like the helpful info you provide in your articles. I’ll bookmark your weblog and check again here regularly. I am quite sure I will learn much new stuff right here! Good luck for the next!
ReplyDelete"web designing course in chennai | web designing classes in chennai "
"web designing training in chennai | web designing institute in chennai "
"web designing and development course | web designing training and placement "
web designer courses in chennai | best institute for web designing Classes in Chennai
Web Designing Institute in Chennai | Web Designing Training in Chennai
Nice information, want to know about Selenium Training In Chennai
ReplyDeleteSelenium Training In Chennai
Data Science Training In Chennai
Protractor Training in Chennai
jmeter training in chennai
Rpa Training Chennai
Rpa Course Chennai
Selenium Training institute In Chennai
Python Training In Chennai
Rpa Training in Chennai
ReplyDeleteRpa Course in Chennai
Blue prism training in Chennai
Data Science Training In Chennai
ReplyDeleteData Science Course In Chennai
Data Science Course In Chennai
Thanks for sharing an informative blog keep rocking bring more details.I like the helpful info you provide in your articles. I’ll bookmark your weblog and check again here regularly. I am quite sure I will learn much new stuff right here! Good luck for the next!
ReplyDeleteWeb Designing Training Institute in Chennai | web design training class in chennai | web designing course in chennai with placement
Mobile Application Development Courses in chennai
Data Science Training in Chennai | Data Science courses in Chennai
Professional packers and movers in chennai | PDY Packers | Household Goods Shifting
Web Designing Training Institute in Chennai | Web Designing courses in Chennai
Google ads services | Google Ads Management agency
Web Designing Course in Chennai | Web Designing Training in Chennai
Home Security Camera 9apps
ReplyDelete9Apps App Search Engine
9apps Rummy App
9apps Whatsapp
9Apps Happy Mod
9apps Whatsapp Business
9apps Dual Space
9apps Files By Google
9apps Facebook Lite
Please refer below if you are looking for best project center in coimbatore
ReplyDeleteJava Training in Coimbatore | Digital Marketing Training in Coimbatore | SEO Training in Coimbatore | Tally Training in Coimbatore | Python Training In Coimbatore | Final Year IEEE Java Projects In Coimbatore | IEEE DOT NET PROJECTS IN COIMBATORE | Final Year IEEE Big Data Projects In Coimbatore | Final Year IEEE Python Projects In Coimbatore
Thank you for excellent article.
Great post. keep sharing such a worthy information
ReplyDeleteSelenium Training in Chennai
Selenium Training in Bangalore
Selenium Training in Coimbatore
Selenium Training Institute in Chennai
Best Selenium Training in Bangalore
Best Selenium Training in Coimbatore
Ethical Hacking Course in Bangalore
Tally Course in Chennai
Thanks for updating this information. Good job.
ReplyDeleteGerman Classes in Chennai
German Language Classes in Chennai
French Classes in Chennai
pearson vue test center in chennai
Informatica Training in Chennai
Data Analytics Courses in Chennai
spanish language in chennai
content writing training in chennai
spanish language course in chennai
German Classes in T Nagar
German Classes in Anna Nagar
I want to learn but I am far behind the skill level to even able take one class of it in college. Iam a 19 year old that wants to learn it.
ReplyDeleteExcelR Digital Marketing Courses In Bangalore
This was an excellent post and very good information provided, Thanks for sharing.
ReplyDeletePython Training in Chennai
Python Training in Bangalore
Python Training in Coimbatore
Python course in bangalore
angular training in bangalore
web design training in coimbatore
python training in hyderabad
Best Python Training in Bangalore
python training in marathahalli
Python Classes in Bangalore
Thanks a lot for sharing such a good source with all, i appreciate your efforts taken for the same. I found this worth sharing and must share this with all.
ReplyDeleteDot Net Training in Chennai | Dot Net Training in anna nagar | Dot Net Training in omr | Dot Net Training in porur | Dot Net Training in tambaram | Dot Net Training in velachery
Such a very useful article. Very interesting to read this article. I would like to thank you for the efforts you had made for writing this awesome article.
ReplyDeleteData Science Course in Pune
Data Science Training in Pune
I feel very grateful that I read this. It is very helpful and very informative and I really learned a lot from it.
ReplyDeleteData Analytics Course in Pune
Data Analytics Training in Pune
I am impressed by the information that you have on this blog. It shows how well you understand this subject.
ReplyDeleteBusiness Analytics Course in Pune
Business Analytics Training in Pune
Clipping Xpert
ReplyDeleteClipping Xpert India
Paragon Clipping Path
Clipping Path Service
Image Editing Company
Ecommerce Image Editing Service
Clipping path company
Clipping Path Service
Image Editing Company
Ecommerce Image Editing Service
Clipping path company
Clipping Path Service
Image Editing Company
Ecommerce Image Editing Service
Clipping path company
This post is very useful! Thanks!
ReplyDeleteData Science Training in Hyderabad
Data Science Course in Hyderabad
This is additionally a generally excellent post which I truly delighted in perusing. It isn't each day that I have the likelihood to see something like this.. data science course in chennai
ReplyDeleteNice Blog!! Thanks For Sharing!!!Wonderful blog & good post. Its really helpful for me, waiting for a more new post. Keep Blogging!
ReplyDeleteServicenow Training In Hyderabad