CVE-2006-2908: High severity mybulletinboard mybulletinboard vulnerability
The domecode function in inc/functionspost.php in MyBulletinBoard (MyBB) 1.1.2, and possibly other versions, allows remote attackers to execute arbitrary PHP code via the username field, which is used in a pregreplace function call with a /e (executable) modifier.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-2908?
CVE-2006-2908 is considered critical due to its potential for remote code execution.
How do I fix CVE-2006-2908?
To fix CVE-2006-2908, upgrade MyBulletinBoard to the latest version that addresses this vulnerability.
What versions of MyBulletinBoard are affected by CVE-2006-2908?
CVE-2006-2908 specifically affects MyBulletinBoard version 1.1.2 and possibly other versions.
What type of vulnerability is CVE-2006-2908?
CVE-2006-2908 is a remote code execution vulnerability stemming from improper handling of user input.
Can CVE-2006-2908 be exploited without authentication?
Yes, CVE-2006-2908 can be exploited remotely without authentication, allowing attackers to execute arbitrary PHP code.