CVE-2007-2211: SQL Injection
Published Apr 24, 2007
·Updated
SQL injection vulnerability in calendar.php in MyBB (aka MyBulletinBoard) 1.2.5 and earlier allows remote attackers to execute arbitrary SQL commands via the day parameter in a dayview action.
Affected Software
1 affected component
MyBulletinBoard MyBulletinBoard<=1.2.5
Event History
Apr 24, 2007
CVE Published
08:19 PM
Apr 25, 2007
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-2211?
CVE-2007-2211 is classified as a high severity SQL injection vulnerability.
2
How do I fix CVE-2007-2211?
To fix CVE-2007-2211, upgrade MyBB to version 1.2.6 or later.
3
What systems are affected by CVE-2007-2211?
CVE-2007-2211 affects MyBB versions up to and including 1.2.5.
4
Can CVE-2007-2211 be exploited remotely?
Yes, CVE-2007-2211 can be exploited remotely by sending crafted requests to the calendar.php script.
5
What type of attack is associated with CVE-2007-2211?
CVE-2007-2211 is associated with SQL injection attacks that can execute arbitrary SQL commands.