CVE-2006-0638: SQL Injection
Published Feb 10, 2006
·Updated
SQL injection vulnerability in moderation.php in MyBB (aka MyBulletinBoard) 1.0.3 allows remote authenticated users, with certain privileges for moderating and merging posts, to execute arbitrary SQL commands via the posts parameter.
Affected Software
1 affected component
MyBulletinBoard MyBulletinBoard=1.0.3
Event History
Feb 10, 2006
CVE Published
11:02 AM
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-0638?
CVE-2006-0638 is classified as a medium severity vulnerability.
2
How do I fix CVE-2006-0638?
To fix CVE-2006-0638, upgrade MyBB to a newer version where the vulnerability is patched.
3
Who is affected by CVE-2006-0638?
CVE-2006-0638 affects remote authenticated users of MyBB 1.0.3 with specific privileges for moderating posts.
4
What type of vulnerability is CVE-2006-0638?
CVE-2006-0638 is an SQL injection vulnerability.
5
Can CVE-2006-0638 allow unauthorized access?
CVE-2006-0638 could potentially allow attackers to execute arbitrary SQL commands, which may compromise the database integrity.