CVE-2006-1065: SQL Injection
Published Mar 7, 2006
·Updated
SQL injection vulnerability in search.php in MyBulletinBoard (MyBB) 1.04 allows remote attackers to execute arbitrary SQL commands via the forums[] parameter.
Affected Software
1 affected component
MyBulletinBoard MyBulletinBoard=1.04
Event History
Mar 7, 2006
CVE Published
10:06 PM
Mar 8, 2006
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-1065?
CVE-2006-1065 is classified as a high severity vulnerability due to its potential for remote SQL injection leading to arbitrary command execution.
2
How do I fix CVE-2006-1065?
To fix CVE-2006-1065, update MyBulletinBoard to version 1.04 or apply proper input validation and sanitization of the forums[] parameter.
3
What systems are affected by CVE-2006-1065?
CVE-2006-1065 specifically affects MyBulletinBoard version 1.04.
4
Can CVE-2006-1065 be exploited remotely?
Yes, CVE-2006-1065 can be exploited remotely by attackers to execute arbitrary SQL commands.
5
What are the risks associated with CVE-2006-1065?
The risks associated with CVE-2006-1065 include unauthorized access to the database, data manipulation, and potential site compromise.