First published: Fri Feb 20 2009(Updated: )
SQL injection vulnerability in pages.php in Custom Pages 1.0 plugin for MyBulletinBoard (MyBB) allows remote attackers to execute arbitrary SQL commands via the page parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mybboard Mybb | ||
Mybboard Custom Pages Plugin | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-6198 is classified as a high severity vulnerability due to its potential for unauthorized SQL command execution.
To fix CVE-2008-6198, update the Custom Pages plugin for MyBulletinBoard to the latest version or apply available patches that address this SQL injection vulnerability.
Users of the Custom Pages 1.0 plugin for MyBulletinBoard (MyBB) are affected by CVE-2008-6198.
Yes, CVE-2008-6198 can be exploited remotely by attackers through crafted page parameters.
Attackers can execute arbitrary SQL commands against the MyBulletinBoard database due to the SQL injection vulnerability in CVE-2008-6198.