CVE-2006-0219: SQL Injection
The original distribution of MyBulletinBoard (MyBB) to update from older versions to 1.0.2 omits or includes older versions of certain critical files, which allows attackers to conduct (1) SQL injection attacks via an attachment name that is not properly handled by inc/functionsupload.php (CVE-2005-4602), and possibly (2) other attacks related to threadmode in usercp.php.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-0219?
CVE-2006-0219 is considered a high severity vulnerability due to its potential for SQL injection attacks.
How do I fix CVE-2006-0219?
To fix CVE-2006-0219, ensure you have updated to the latest version of MyBulletinBoard with patched critical files.
What are the affected versions of MyBulletinBoard in CVE-2006-0219?
The affected versions in CVE-2006-0219 include MyBulletinBoard 1.0 final, 1.01, and 1.0.2.
What type of attack does CVE-2006-0219 allow?
CVE-2006-0219 allows attackers to conduct SQL injection attacks through manipulated attachment names.
Is my MyBulletinBoard installation vulnerable to CVE-2006-0219?
If you're using any of the affected versions mentioned in CVE-2006-0219, your installation is vulnerable and should be updated.