PT-2006-1296 · Mybb · Mybb

Neg127

·

Published

2006-01-16

·

Updated

2017-07-20

·

CVE-2006-0219

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions MyBB versions prior to 1.0.2
Description The issue allows attackers to conduct SQL injection attacks via an attachment name that is not properly handled by inc/functions upload.php. This could also lead to other attacks related to threadmode in usercp.php.
Recommendations For versions prior to 1.0.2, update to version 1.0.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the inc/functions upload.php file and the usercp.php file to minimize the risk of exploitation. Avoid using vulnerable attachment names in the affected API endpoint until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-0219

Affected Products

Mybb