HIGH
Multiple SQL injection vulnerabilities in MyBB (aka MyBulletinBoard) before 1.6.1 allow remote attackers to execute arbitrary SQL commands via the keywords parameter in a (1) do_search action to search.php or (2) do_stuff action to private.php
Published Aug 13, 2012
7.5
HIGHCVSS 2.0
EPSS 5.58%
Description
Multiple SQL injection vulnerabilities in MyBB (aka MyBulletinBoard) before 1.6.1 allow remote attackers to execute arbitrary SQL commands via the keywords parameter in a (1) do_search action to search.php or (2) do_stuff action to private.php. NOTE: the vendor disputes this issue, saying "Although this doesn't lead to an SQL injection, it does provide a general MyBB SQL error.
Affected products
No data.
OR
- ≤ 1.6.0
- 1.00
- 1.0
- 1.0
- 1.0
- 1.0
- 1.0
- 1.0
- 1.0
- 1.01
- 1.1.0
- 1.1.1
- 1.1.2
- 1.1.3
- 1.1.4
- 1.1.5
- 1.1.6
- 1.1.7
- 1.1.8
- 1.02
- 1.2
- 1.2.0
- 1.2.1
- 1.2.2
- 1.2.3
- 1.2.4
- 1.2.5
- 1.2.6
- 1.2.7
- 1.2.8
- 1.2.9
- 1.2.10
- 1.2.11
- 1.2.12
- 1.2.13
- 1.2.14
- 1.03
- 1.3
- 1.04
- 1.4.0
- 1.4.1
- 1.4.2
- 1.4.3
- 1.4.4
- 1.4.5
- 1.4.6
- 1.4.7
- 1.4.8
- 1.4.9
- 1.4.10
- 1.4.11
- 1.4.12
- 1.4.13
- 1.4.14
- 1.4.15
- 1.4.16
- 1.5.1
- 1.5.2
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (8)
- http://dev.mybb.com/issues/1330 x_refsource_MISC
- http://www.openwall.com/lists/oss-security/2012/03/23/4 mailing-listx_refsource_MLIST
- http://www.openwall.com/lists/oss-security/2012/03/25/1 mailing-listx_refsource_MLIST
- http://www.openwall.com/lists/oss-security/2012/05/08/3 mailing-listx_refsource_MLIST
- http://www.openwall.com/lists/oss-security/2012/05/08/7 mailing-listx_refsource_MLIST
- http://www.osvdb.org/70013 vdb-entryx_refsource_OSVDB
- http://www.osvdb.org/70014 vdb-entryx_refsource_OSVDB
- http://www.securityfocus.com/bid/45565 vdb-entryx_refsource_BID
| Link | Providers | Tags |
|---|---|---|
| http://dev.mybb.com/issues/1330 | x_refsource_MISC | |
| http://www.openwall.com/lists/oss-security/2012/03/23/4 | mailing-listx_refsource_MLIST | |
| http://www.openwall.com/lists/oss-security/2012/03/25/1 | mailing-listx_refsource_MLIST | |
| http://www.openwall.com/lists/oss-security/2012/05/08/3 | mailing-listx_refsource_MLIST | |
| http://www.openwall.com/lists/oss-security/2012/05/08/7 | mailing-listx_refsource_MLIST | |
| http://www.osvdb.org/70013 | vdb-entryx_refsource_OSVDB | |
| http://www.osvdb.org/70014 | vdb-entryx_refsource_OSVDB | |
| http://www.securityfocus.com/bid/45565 | vdb-entryx_refsource_BID |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Aug 13, 2012
Updated Sep 17, 2024
Reserved Apr 30, 2012
Link CVE-2010-5096
CISA Vulnrichment
Updated May 8, 2024