First published: Tue Apr 24 2007(Updated: )
Multiple SQL injection vulnerabilities in calendar.php in MyBB (aka MyBulletinBoard) 1.2.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) year or (2) month parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mybb Mybb | =1.2.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-2212 is classified as a high severity vulnerability due to its potential for remote SQL injection leading to unauthorized access or data manipulation.
To fix CVE-2007-2212, upgrade MyBB to version 1.2.6 or later, as these versions contain patches for the SQL injection vulnerabilities.
CVE-2007-2212 can facilitate various SQL injection attacks, allowing attackers to execute arbitrary SQL commands against the database.
CVE-2007-2212 affects MyBB version 1.2.5 and earlier releases.
There is no standalone patch for CVE-2007-2212; you must upgrade to a non-vulnerable version of MyBB to mitigate the risk.