Show filters
12 Total Results
Displaying 1-10 of 12
Sort by:
Attacker Value
Unknown

CVE-2009-2230

Disclosure Date: June 26, 2009 (last updated October 04, 2023)
SQL injection vulnerability in inc/datahandlers/user.php in MyBB (aka MyBulletinBoard) before 1.4.7 allows remote authenticated users to execute arbitrary SQL commands via the birthdayprivacy parameter.
0
Attacker Value
Unknown

CVE-2008-0787

Disclosure Date: February 15, 2008 (last updated October 04, 2023)
SQL injection vulnerability in inc/datahandlers/pm.php in MyBB before 1.2.12 allows remote authenticated users to execute arbitrary SQL commands via the options[disablesmilies] parameter to private.php.
0
Attacker Value
Unknown

CVE-2008-0382

Disclosure Date: January 22, 2008 (last updated October 04, 2023)
Multiple eval injection vulnerabilities in MyBB 1.2.10 and earlier allow remote attackers to execute arbitrary code via the sortby parameter to (1) forumdisplay.php or (2) a results action in search.php.
0
Attacker Value
Unknown

CVE-2006-4972

Disclosure Date: September 25, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in archive/index.php/forum-4.html in MyBB (aka MyBulletinBoard) allows remote attackers to inject arbitrary web script or HTML via the navbits[][name] parameter.
0
Attacker Value
Unknown

CVE-2006-4971

Disclosure Date: September 25, 2006 (last updated October 04, 2023)
MyBB (aka MyBulletinBoard) allows remote attackers to obtain sensitive information via a direct request for inc/plugins/hello.php, which reveals the path in an error message.
0
Attacker Value
Unknown

CVE-2006-3953

Disclosure Date: August 01, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in usercp.php in MyBB (aka MyBulletinBoard) 1.x allows remote attackers to inject arbitrary web script or HTML via the gallery parameter.
0
Attacker Value
Unknown

CVE-2006-3954

Disclosure Date: August 01, 2006 (last updated October 04, 2023)
Directory traversal vulnerability in usercp.php in MyBB (aka MyBulletinBoard) 1.x allows remote attackers to read arbitrary files via a .. (dot dot) in the gallery parameter in a (1) avatar or (2) do_avatar action.
0
Attacker Value
Unknown

CVE-2006-3759

Disclosure Date: July 21, 2006 (last updated October 04, 2023)
Unspecified vulnerability in MyBB (aka MyBulletinBoard) 1.1.4, related has unspecified impact and attack vectors related to "user group manipulation."
0
Attacker Value
Unknown

CVE-2006-3758

Disclosure Date: July 21, 2006 (last updated October 04, 2023)
inc/init.php in Archive Mode (Light) in MyBB (aka MyBulletinBoard) 1.1.4 calls the extract function with EXTR_OVERWRITE on HTTP POST and GET variables, which allows remote attackers to overwrite arbitrary variables, as demonstrated via an SQL injection using the _SERVER[HTTP_CLIENT_IP] parameter in archive/index.php.
0
Attacker Value
Unknown

CVE-2006-3761

Disclosure Date: July 21, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in inc/functions_post.php in MyBB (aka MyBulletinBoard) 1.0 RC2 through 1.1.4 allows remote attackers to inject arbitrary web script or HTML via a javascript URI with an SGML numeric character reference in the url BBCode tag, as demonstrated using "javascript".
0