CVE-2006-0218: SQL Injection
Multiple unspecified vulnerabilities in MyBulletinBoard (MyBB) before 1.0.2 have unspecified impact and attack vectors, related to (1) admin/moderate.php, (2) admin/themes.php, (3) inc/functions.php, (4) inc/functionsupload.php, (5) printthread.php, and (6) usercp.php, and probably related to SQL injection. NOTE: it is likely that this issue subsumes CVE-2005-4602 and CVE-2005-4603. However, since the vendor advisory is vague and additional files are mentioned, is is likely that this contains at least one distinct vulnerability from CVE-2005-4602 and CVE-2005-4603.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-0218?
The severity of CVE-2006-0218 is currently unspecified, but it involves multiple vulnerabilities in MyBulletinBoard before version 1.0.2.
How do I fix CVE-2006-0218?
To fix CVE-2006-0218, update MyBulletinBoard to version 1.0.2 or later.
What versions are affected by CVE-2006-0218?
CVE-2006-0218 affects MyBB versions prior to 1.0.2, including several release candidates and beta versions.
What components are impacted by CVE-2006-0218?
CVE-2006-0218 impacts various components including admin/moderate.php, admin/themes.php, and inc/functions.php.
Is there any known exploit for CVE-2006-0218?
The specific attack vectors for CVE-2006-0218 are unspecified, but the vulnerabilities could potentially be exploited.