MyBB (aka MyBulletinBoard) 1.4.2 does not properly handle an uploaded file with a nonstandard file type that contains HTML sequences, which allows remote attackers to cause that file to be processed as HTML by Internet Explorer's content inspection, aka "Incomplete protection against MIME-sniffing." NOTE: this could be leveraged for XSS and other attacks.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://archives.neohapsis.com/archives/bugtraq/2008-10/0203.html | mailing list |
http://archives.neohapsis.com/archives/fulldisclosure/2008-10/0472.html | mailing list |
http://www.openwall.com/lists/oss-security/2008/11/01/2 | mailing list |