CVE-2005-2778: SQL Injection
Published Sep 2, 2005
·Updated
SQL injection vulnerability in member.php in MyBulletinBoard (MyBB) allows remote attackers to execute arbitrary SQL statements via the fid parameter.
Affected Software
4 affected components
MyBulletinBoard MyBulletinBoard=rc3
MyBulletinBoard MyBulletinBoard=rc2
MyBulletinBoard MyBulletinBoard=rc1
MyBulletinBoard MyBulletinBoard=rc4
Event History
Sep 2, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-2778?
CVE-2005-2778 has a medium severity level due to its potential for SQL injection attacks.
2
How do I fix CVE-2005-2778?
To fix CVE-2005-2778, users should upgrade to a patched version of MyBB that addresses the SQL injection flaw.
3
Which versions of MyBB are affected by CVE-2005-2778?
CVE-2005-2778 affects MyBB versions rc1, rc2, rc3, and rc4.
4
What types of attacks can occur due to CVE-2005-2778?
CVE-2005-2778 allows remote attackers to execute arbitrary SQL statements, potentially compromising the database.
5
Is CVE-2005-2778 remotely exploitable?
Yes, CVE-2005-2778 is remotely exploitable since it allows attackers to send malicious requests via the fid parameter.