PT-2006-1998 · Mybb · Mybb

Devil-00

·

Published

2006-03-02

·

Updated

2018-10-18

·

CVE-2006-0959

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions MyBB versions 1.03 through 1.04
Description A SQL injection issue exists, allowing remote attackers to execute arbitrary SQL commands. This occurs when the register globals setting is enabled, and the comma variable value is set via the comma parameter in a cookie.
Recommendations For MyBB versions 1.03 through 1.04, consider disabling the register globals setting to mitigate the risk of SQL injection attacks. As a temporary workaround, restrict access to the misc.php file until a patch is available. Avoid using the comma parameter in cookies for the affected API endpoint until the issue is resolved.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2006-0959

Affected Products

Mybb