CVE-2013-6936: SQL Injection
Published Dec 4, 2013
·Updated
Multiple SQL injection vulnerabilities in ajaxfs.php in the Ajax forum stat (Ajaxfs) Plugin 2.0 for MyBB (aka MyBulletinBoard) allow remote attackers to execute arbitrary SQL commands via the (1) tooltip or (2) usertooltip parameter.
Affected Software
1 affected component
MyBB Ajax Forum Stat Mybb=2.0
Event History
Dec 4, 2013
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·06:56 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-6936?
CVE-2013-6936 is considered a high-severity vulnerability due to its potential for remote SQL command execution.
2
How do I fix CVE-2013-6936?
To fix CVE-2013-6936, update the Ajax Forum Stat plugin to a version that addresses SQL injection vulnerabilities.
3
What are the affected versions for CVE-2013-6936?
CVE-2013-6936 affects MyBB Ajax Forum Stat plugin version 2.0.
4
Can CVE-2013-6936 be exploited remotely?
Yes, CVE-2013-6936 can be exploited remotely by attackers through crafted HTTP requests.
5
What impact does CVE-2013-6936 have on MyBB users?
CVE-2013-6936 allows attackers to execute arbitrary SQL commands, potentially compromising the database and sensitive information.