Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown

CVE-2009-2230

Disclosure Date: June 26, 2009 (last updated October 04, 2023)
SQL injection vulnerability in inc/datahandlers/user.php in MyBB (aka MyBulletinBoard) before 1.4.7 allows remote authenticated users to execute arbitrary SQL commands via the birthdayprivacy parameter.
0
Attacker Value
Unknown

CVE-2008-0787

Disclosure Date: February 15, 2008 (last updated October 04, 2023)
SQL injection vulnerability in inc/datahandlers/pm.php in MyBB before 1.2.12 allows remote authenticated users to execute arbitrary SQL commands via the options[disablesmilies] parameter to private.php.
0
Attacker Value
Unknown

CVE-2008-0382

Disclosure Date: January 22, 2008 (last updated October 04, 2023)
Multiple eval injection vulnerabilities in MyBB 1.2.10 and earlier allow remote attackers to execute arbitrary code via the sortby parameter to (1) forumdisplay.php or (2) a results action in search.php.
0