CVE-2006-0523: SQL Injection
Published Feb 2, 2006
·Updated
SQL injection vulnerability in global.php in MyBB before 1.03 allows remote attackers to execute arbitrary SQL commands via the templatelist variable.
Affected Software
7 affected components
MyBulletinBoard MyBulletinBoard=1.0_final
MyBulletinBoard MyBulletinBoard=1.0_rc4
MyBulletinBoard MyBulletinBoard=1.0_pr2
MyBulletinBoard MyBulletinBoard=1.0.1
MyBulletinBoard MyBulletinBoard=1.0.2
MyBulletinBoard MyBulletinBoard=1.0_rc2
MyBulletinBoard MyBulletinBoard=1.0_preview_release_2
Remediation
Patch Available
Event History
Feb 2, 2006
CVE Published
11:02 AM
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-0523?
CVE-2006-0523 is considered a high severity SQL injection vulnerability.
2
How do I fix CVE-2006-0523?
To fix CVE-2006-0523, upgrade MyBB to version 1.0.3 or later.
3
What versions of MyBB are affected by CVE-2006-0523?
CVE-2006-0523 affects MyBB versions 1.0_final, 1.0_rc4, 1.0_pr2, 1.0.1, 1.0.2, 1.0_rc2, and 1.0_preview_release_2.
4
Can CVE-2006-0523 allow attackers to access sensitive data?
Yes, CVE-2006-0523 can allow attackers to execute arbitrary SQL commands, potentially leading to access to sensitive data.
5
Is there a risk of remote exploitation with CVE-2006-0523?
Yes, CVE-2006-0523 can be exploited remotely, making it critical to address the vulnerability.