First published: Fri Feb 15 2008(Updated: )
SQL injection vulnerability in inc/datahandlers/pm.php in MyBB before 1.2.12 allows remote authenticated users to execute arbitrary SQL commands via the options[disablesmilies] parameter to private.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mybulletinboard | =1.0 | |
Mybulletinboard | =1.0.1 | |
Mybulletinboard | =1.0.2 | |
Mybulletinboard | =1.0.3 | |
Mybulletinboard | =1.0.4 | |
Mybulletinboard | =1.0_pr2 | |
Mybulletinboard | =1.1 | |
Mybulletinboard | =1.1.1 | |
Mybulletinboard | =1.1.2 | |
Mybulletinboard | =1.1.3 | |
Mybulletinboard | =1.1.4 | |
Mybulletinboard | =1.1.5 | |
Mybulletinboard | =1.1.6 | |
Mybulletinboard | =1.1.7 | |
Mybulletinboard | =1.1.8 | |
Mybulletinboard | =1.2 | |
Mybulletinboard | =1.2.3 | |
Mybulletinboard | =1.2.5 | |
Mybulletinboard | =1.2.10 | |
Mybulletinboard | =1.2.11 | |
Mybulletinboard | =1.10 | |
Mybulletinboard | =rc1 | |
Mybulletinboard | =rc2 | |
Mybulletinboard | =rc3 | |
Mybulletinboard | =rc4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-0787 is considered a high severity vulnerability due to its potential to allow remote authenticated users to execute arbitrary SQL commands.
To fix CVE-2008-0787, upgrade MyBB to version 1.2.12 or later, which contains the necessary security patches.
CVE-2008-0787 affects all MyBB versions prior to 1.2.12, including versions 1.10, 1.1.1, and earlier versions.
CVE-2008-0787 can facilitate SQL injection attacks, which may compromise database integrity and expose sensitive data.
While applying the patch is the best solution, temporarily restrict access to the affected functionality or monitor for anomalous behavior as a mitigation.