Mybb · Advanced Forum Signatures · CVE-2011-5278
**Name of the Vulnerable Software and Affected Versions**
Advanced Forum Signatures plugin version 2.0.4
**Description**
The issue allows remote attackers to execute arbitrary SQL commands. This is achieved via the `afs bar right` parameter in the signature.php file of the Advanced Forum Signatures plugin for MyBB.
**Recommendations**
For version 2.0.4, avoid using the `afs bar right` parameter in the signature.php file until a fix is available. Consider restricting access to the signature.php file to minimize the risk of exploitation.