CVE-2012-2324: SQL Injection
Multiple SQL injection vulnerabilities in MyBB (aka MyBulletinBoard) before 1.6.7 allow remote administrators to execute arbitrary SQL commands via unspecified vectors in the (1) user search or (2) Mail Log in the Admin Control Panel (ACP).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2324?
CVE-2012-2324 is considered a high severity vulnerability due to the potential for remote execution of arbitrary SQL commands.
How do I fix CVE-2012-2324?
To remediate CVE-2012-2324, upgrade MyBB to version 1.6.7 or later, which contains security fixes addressing this vulnerability.
Which versions of MyBB are affected by CVE-2012-2324?
CVE-2012-2324 affects all MyBB versions prior to 1.6.7, including versions as early as 1.0 up to 1.6.6.
What type of vulnerability is CVE-2012-2324?
CVE-2012-2324 is classified as an SQL injection vulnerability, allowing attackers to execute unauthorized SQL commands.
Who can be impacted by CVE-2012-2324?
Remote administrators utilizing affected versions of MyBB may be particularly vulnerable to exploitation via CVE-2012-2324.