Vulnerabilities
Vulnerable Software
SQL injection vulnerability in inc/datahandlers/user.php in MyBB (aka MyBulletinBoard) before 1.4.7 allows remote authenticated users to execute arbitrary SQL commands via the birthdayprivacy parameter.
CVSS Score
7.5
EPSS Score
0.016
Published
2009-06-26
SQL injection vulnerability in inc/datahandlers/pm.php in MyBB before 1.2.12 allows remote authenticated users to execute arbitrary SQL commands via the options[disablesmilies] parameter to private.php.
CVSS Score
6.5
EPSS Score
0.016
Published
2008-02-15
Multiple eval injection vulnerabilities in MyBB 1.2.10 and earlier allow remote attackers to execute arbitrary code via the sortby parameter to (1) forumdisplay.php or (2) a results action in search.php.
CVSS Score
7.5
EPSS Score
0.731
Published
2008-01-22
member.php in MyBB (aka MyBulletinBoard), when debug mode is available, allows remote authenticated users to change the password of any account by providing the account's registered e-mail address in a debug request for a do_lostpw action, which prints the change password verification code in the debug output.
CVSS Score
6.0
EPSS Score
0.005
Published
2007-04-11


Contact Us

Shodan ® - All rights reserved