First published: Fri Sep 02 2005(Updated: )
SQL injection vulnerability in member.php in MyBulletinBoard (MyBB) allows remote attackers to execute arbitrary SQL statements via the fid parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mybulletinboard Mybulletinboard | =rc3 | |
Mybulletinboard Mybulletinboard | =rc2 | |
Mybulletinboard Mybulletinboard | =rc1 | |
Mybulletinboard Mybulletinboard | =rc4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2778 has a medium severity level due to its potential for SQL injection attacks.
To fix CVE-2005-2778, users should upgrade to a patched version of MyBB that addresses the SQL injection flaw.
CVE-2005-2778 affects MyBB versions rc1, rc2, rc3, and rc4.
CVE-2005-2778 allows remote attackers to execute arbitrary SQL statements, potentially compromising the database.
Yes, CVE-2005-2778 is remotely exploitable since it allows attackers to send malicious requests via the fid parameter.