PT-2006-3298 · Mybb · Mybb

Addmimistrator

·

Published

2006-05-12

·

Updated

2018-10-18

·

CVE-2006-2333

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions MyBB version 1.1.1
Description The issue allows remote attackers to execute arbitrary SQL commands via the e-mail address when registering for a forum that requires e-mail verification. This is due to improper handling in usercp.php and member.php.
Recommendations For MyBB version 1.1.1, as a temporary workaround, consider restricting access to the user registration process that requires e-mail verification until a proper fix is applied. Additionally, restrict input handling in usercp.php and member.php to minimize the risk of SQL injection.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-2333

Affected Products

Mybb