First published: Thu Aug 25 2005(Updated: )
SQL injection vulnerability in search.php for MyBulletinBoard (MyBB) 1.00 Release Candidate 1 through 4 allows remote attackers to execute arbitrary SQL commands via the uid parameter. NOTE: this issue might overlap CVE-2005-0282.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mybulletinboard Mybulletinboard | =1.00_rc4 | |
Mybulletinboard Mybulletinboard | =1.00_rc3 | |
Mybulletinboard Mybulletinboard | =1.00_rc1 | |
Mybulletinboard Mybulletinboard | =1.00_rc2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2697 is classified as a high severity vulnerability due to its potential to allow remote attackers to execute arbitrary SQL commands.
To fix CVE-2005-2697, upgrade to a later version of MyBulletinBoard that is not affected by this SQL injection issue.
CVE-2005-2697 affects MyBulletinBoard version 1.00 Release Candidate 1 through 4.
CVE-2005-2697 is an SQL injection vulnerability that can lead to unauthorized database access.
Attackers exploiting CVE-2005-2697 can execute arbitrary SQL commands, potentially compromising the database.