CVE-2005-2697: SQL Injection
SQL injection vulnerability in search.php for MyBulletinBoard (MyBB) 1.00 Release Candidate 1 through 4 allows remote attackers to execute arbitrary SQL commands via the uid parameter. NOTE: this issue might overlap CVE-2005-0282.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2005-2697?
CVE-2005-2697 is classified as a high severity vulnerability due to its potential to allow remote attackers to execute arbitrary SQL commands.
How do I fix CVE-2005-2697?
To fix CVE-2005-2697, upgrade to a later version of MyBulletinBoard that is not affected by this SQL injection issue.
Which versions of MyBulletinBoard are affected by CVE-2005-2697?
CVE-2005-2697 affects MyBulletinBoard version 1.00 Release Candidate 1 through 4.
What type of vulnerability is CVE-2005-2697?
CVE-2005-2697 is an SQL injection vulnerability that can lead to unauthorized database access.
What can attackers do with CVE-2005-2697?
Attackers exploiting CVE-2005-2697 can execute arbitrary SQL commands, potentially compromising the database.