MyBB Community Forums

Full Version: MyBB tabs plugin created by Ethan BUG!!!
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
Hello

I own one hacking forum with many members. One of my staff guys try to find vuln , and he found one <snip> sqli bug.

Listen , who have mybb plugin tabs created by ethan better to remove it.
Here proof :

http://yourforum.com/index.php?tab=2

make it like this :
http://yourforum.com/index.php?tab=2'

and you will get :
SQL Error:
1064 - You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ''2''' at line 1 !!!
Thanks
DR.SQL
yup, I found it too....but I thought it's only me....but I don't use it anymore Wink