CVE-2008-0382: Code Injection
Published Jan 22, 2008
·Updated
Multiple eval injection vulnerabilities in MyBB 1.2.10 and earlier allow remote attackers to execute arbitrary code via the sortby parameter to (1) forumdisplay.php or (2) a results action in search.php.
Affected Software
19 affected components
MyBulletinBoard MyBulletinBoard=1.0
MyBulletinBoard MyBulletinBoard=1.0.1
MyBulletinBoard MyBulletinBoard=1.0.2
MyBulletinBoard MyBulletinBoard=1.0.3
MyBulletinBoard MyBulletinBoard=1.0.4
MyBulletinBoard MyBulletinBoard=1.0_pr2
MyBulletinBoard MyBulletinBoard=1.1
MyBulletinBoard MyBulletinBoard=1.1.1
MyBulletinBoard MyBulletinBoard=1.1.2
MyBulletinBoard MyBulletinBoard=1.1.3
MyBulletinBoard MyBulletinBoard=1.1.4
MyBulletinBoard MyBulletinBoard=1.1.5
MyBulletinBoard MyBulletinBoard=1.1.7
MyBulletinBoard MyBulletinBoard=1.1.8
MyBulletinBoard MyBulletinBoard=1.2
MyBulletinBoard MyBulletinBoard=1.2.3
MyBulletinBoard MyBulletinBoard=1.2.5
MyBulletinBoard MyBulletinBoard=1.2.10
MyBulletinBoard MyBulletinBoard=1.10
Event History
Jan 22, 2008
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-0382?
CVE-2008-0382 is classified as a high severity vulnerability due to its potential to allow remote code execution.
2
How do I fix CVE-2008-0382?
To fix CVE-2008-0382, upgrade MyBB to version 1.2.11 or later, which addresses these vulnerabilities.
3
What software versions are affected by CVE-2008-0382?
CVE-2008-0382 affects MyBB versions 1.0 to 1.2.10.
4
What types of attacks can exploit CVE-2008-0382?
CVE-2008-0382 can be exploited through remote code execution by manipulating the 'sortby' parameter.
5
Is CVE-2008-0382 still a risk if my MyBB installation is updated?
No, updating to MyBB version 1.2.11 or later will mitigate the risk associated with CVE-2008-0382.