Vulnerabilities
Vulnerable Software
Mybboard:  >> Mybb  >> 1.4.3  Security Vulnerabilities
Multiple SQL injection vulnerabilities in MyBB (aka MyBulletinBoard) before 1.6.1 allow remote attackers to execute arbitrary SQL commands via the keywords parameter in a (1) do_search action to search.php or (2) do_stuff action to private.php. NOTE: the vendor disputes this issue, saying "Although this doesn't lead to an SQL injection, it does provide a general MyBB SQL error.
CVSS Score
7.5
EPSS Score
0.072
Published
2012-08-13
MyBB (aka MyBulletinBoard) 1.4.3 includes the sensitive my_post_key parameter in URLs to moderation.php with the (1) mergeposts, (2) split, and (3) deleteposts actions, which allows remote attackers to steal the token and bypass the cross-site request forgery (CSRF) protection mechanism to hijack the authentication of moderators by reading the token from the HTTP Referer header.
CVSS Score
6.8
EPSS Score
0.001
Published
2009-08-25
SQL injection vulnerability in pages.php in Custom Pages 1.0 plugin for MyBulletinBoard (MyBB) allows remote attackers to execute arbitrary SQL commands via the page parameter.
CVSS Score
7.5
EPSS Score
0.001
Published
2009-02-20


Contact Us

Shodan ® - All rights reserved