Index: security/vuxml/vuln.xml =================================================================== --- security/vuxml/vuln.xml +++ security/vuxml/vuln.xml @@ -58,6 +58,37 @@ * Do not forget port variants (linux-f10-libxml2, libxml2, etc.) --> + + mybb -- multiple vulnerabilities + + + mybb + 1.8.13 + + + + +

MyBB Team reports:

+
+

High risk: Installer RCE on configuration file write

+

High risk: Language file headers RCE

+

Medium risk: Installer XSS

+

Medium risk: Mod CP Edit Profile XSS

+

Low risk: Insufficient moderator permission check in delayed moderation tools

+

Low risk: Announcements HTML filter bypass

+

Low risk: Language Pack Properties XSS

+
+ +
+ + https://blog.mybb.com/2017/11/07/mybb-1-8-13-released-security-maintenance-release/ + + + 2017-11-07 + 2017-11-24 + +
+ roundcube -- file disclosure vulnerability Index: www/mybb/Makefile =================================================================== --- www/mybb/Makefile +++ www/mybb/Makefile @@ -2,7 +2,7 @@ # $FreeBSD$ PORTNAME= mybb -PORTVERSION= 1.8.12 +PORTVERSION= 1.8.13 CATEGORIES= www MAINTAINER= joneum@FreeBSD.org @@ -12,12 +12,12 @@ LICENSE_FILE= ${WRKSRC}/LICENSE USE_GITHUB= yes -GH_TAGNAME= ${PORTNAME}_1812 +GH_TAGNAME= ${PORTNAME}_1813 -USES= cpe mysql php +USES= cpe mysql php:web NO_BUILD= yes NO_ARCH= yes -USE_PHP= xsl mysql iconv gd xml +USE_PHP= xsl mysqli iconv gd xml SUB_FILES= pkg-message WWWDIR?= ${PREFIX}/www/${PORTNAME} PLIST_SUB= WWWOWN=${WWWOWN} Index: www/mybb/distinfo =================================================================== --- www/mybb/distinfo +++ www/mybb/distinfo @@ -1,3 +1,3 @@ -TIMESTAMP = 1495628407 -SHA256 (mybb-mybb-1.8.12-mybb_1812_GH0.tar.gz) = ed142eb23de8c04caf4008ff12add85d54ed9ecbe32c6633e690b2cf6c0d10e0 -SIZE (mybb-mybb-1.8.12-mybb_1812_GH0.tar.gz) = 1842475 +TIMESTAMP = 1511544780 +SHA256 (mybb-mybb-1.8.13-mybb_1813_GH0.tar.gz) = bcd0db9eae91df077bf77fd2b5f6910ca8fe797ee168a9b7521b90c916cd6ef5 +SIZE (mybb-mybb-1.8.13-mybb_1813_GH0.tar.gz) = 1875884 Index: www/mybb/pkg-plist =================================================================== --- www/mybb/pkg-plist +++ www/mybb/pkg-plist @@ -1,5 +1,4 @@ -@owner www -@group www +%%WWWDIR%%/.gitattributes %%WWWDIR%%/.gitignore %%WWWDIR%%/CONTRIBUTING.md %%WWWDIR%%/LICENSE @@ -30,6 +29,7 @@ %%WWWDIR%%/admin/jscripts/codemirror/addon/fold/xml-fold.js %%WWWDIR%%/admin/jscripts/codemirror/addon/index.html %%WWWDIR%%/admin/jscripts/codemirror/addon/search/index.html +%%WWWDIR%%/admin/jscripts/codemirror/addon/search/jump-to-line.js %%WWWDIR%%/admin/jscripts/codemirror/addon/search/match-highlighter.js %%WWWDIR%%/admin/jscripts/codemirror/addon/search/matchesonscrollbar.css %%WWWDIR%%/admin/jscripts/codemirror/addon/search/matchesonscrollbar.js @@ -40,6 +40,8 @@ %%WWWDIR%%/admin/jscripts/codemirror/lib/codemirror.js %%WWWDIR%%/admin/jscripts/codemirror/lib/index.html %%WWWDIR%%/admin/jscripts/codemirror/mode/css/css.js +%%WWWDIR%%/admin/jscripts/codemirror/mode/css/gss.html +%%WWWDIR%%/admin/jscripts/codemirror/mode/css/gss_test.js %%WWWDIR%%/admin/jscripts/codemirror/mode/css/index.html %%WWWDIR%%/admin/jscripts/codemirror/mode/css/less.html %%WWWDIR%%/admin/jscripts/codemirror/mode/css/less_test.js @@ -59,9 +61,6 @@ %%WWWDIR%%/admin/jscripts/codemirror/theme/index.html %%WWWDIR%%/admin/jscripts/codemirror/theme/mybb.css %%WWWDIR%%/admin/jscripts/index.html -%%WWWDIR%%/admin/jscripts/jqueryui/css/redmond/images/animated-overlay.gif -%%WWWDIR%%/admin/jscripts/jqueryui/css/redmond/images/ui-bg_flat_0_aaaaaa_40x100.png -%%WWWDIR%%/admin/jscripts/jqueryui/css/redmond/images/ui-bg_flat_55_fbec88_40x100.png %%WWWDIR%%/admin/jscripts/jqueryui/css/redmond/images/ui-bg_glass_75_d0e5f5_1x400.png %%WWWDIR%%/admin/jscripts/jqueryui/css/redmond/images/ui-bg_glass_85_dfeffc_1x400.png %%WWWDIR%%/admin/jscripts/jqueryui/css/redmond/images/ui-bg_glass_95_fef1ec_1x400.png @@ -380,6 +379,7 @@ %%WWWDIR%%/inc/3rdparty/diff/Diff/Renderer/Context.php %%WWWDIR%%/inc/3rdparty/diff/Diff/Renderer/Inline.php %%WWWDIR%%/inc/3rdparty/diff/Diff/Renderer/Unified.php +%%WWWDIR%%/inc/3rdparty/diff/Diff/Renderer/Unified/Colored.php %%WWWDIR%%/inc/3rdparty/diff/Diff/Renderer/index.html %%WWWDIR%%/inc/3rdparty/diff/Diff/String.php %%WWWDIR%%/inc/3rdparty/diff/Diff/ThreeWay.php @@ -648,6 +648,7 @@ %%WWWDIR%%/install/resources/upgrade39.php %%WWWDIR%%/install/resources/upgrade4.php %%WWWDIR%%/install/resources/upgrade40.php +%%WWWDIR%%/install/resources/upgrade41.php %%WWWDIR%%/install/resources/upgrade5.php %%WWWDIR%%/install/resources/upgrade6.php %%WWWDIR%%/install/resources/upgrade7.php @@ -662,6 +663,7 @@ %%WWWDIR%%/jscripts/index.html %%WWWDIR%%/jscripts/inline_edit.js %%WWWDIR%%/jscripts/inline_moderation.js +%%WWWDIR%%/jscripts/inline_reports.js %%WWWDIR%%/jscripts/jeditable/jeditable.min.js %%WWWDIR%%/jscripts/jquery.js %%WWWDIR%%/jscripts/jquery.plugins.js