PT-2006-3298 · Mybb · Mybb
Addmimistrator
·
Published
2006-05-12
·
Updated
2018-10-18
·
CVE-2006-2333
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
MyBB version 1.1.1
Description
The issue allows remote attackers to execute arbitrary SQL commands via the e-mail address when registering for a forum that requires e-mail verification. This is due to improper handling in usercp.php and member.php.
Recommendations
For MyBB version 1.1.1, as a temporary workaround, consider restricting access to the user registration process that requires e-mail verification until a proper fix is applied. Additionally, restrict input handling in usercp.php and member.php to minimize the risk of SQL injection.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mybb