CVE-2005-4602: SQL Injection
SQL injection vulnerability in inc/functionupload.php in MyBB before 1.0.1 allows remote attackers to execute arbitrary SQL commands via the file extension of an uploaded file attachment.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2005-4602?
CVE-2005-4602 is classified as a medium severity vulnerability due to the potential for SQL injection, allowing unauthorized access to the database.
How do I fix CVE-2005-4602?
To fix CVE-2005-4602, upgrade MyBB to version 1.0.1 or later that includes the security patch addressing this vulnerability.
What systems are affected by CVE-2005-4602?
CVE-2005-4602 affects MyBB versions prior to 1.0.1, specifically including 1.0_rc1, 1.0_rc2, 1.0_rc3, and 1.0_rc4.
What type of attack can exploit CVE-2005-4602?
CVE-2005-4602 can be exploited through SQL injection, allowing attackers to execute arbitrary SQL commands via manipulated file attachments.
Is CVE-2005-4602 a known vulnerability?
Yes, CVE-2005-4602 has been documented and is a known vulnerability in earlier versions of MyBB.