CVE-2014-9240: SQL Injection
Published Dec 3, 2014
·Updated
SQL injection vulnerability in member.php in MyBB (aka MyBulletinBoard) 1.8.x before 1.8.2 allows remote attackers to execute arbitrary SQL commands via the questionid parameter in a doregister action.
Affected Software
2 affected components
Mybb Mybb=1.8.0
Mybb Mybb=1.8.1
Remediation
Event History
Dec 3, 2014
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-9240?
CVE-2014-9240 is classified as a critical SQL injection vulnerability allowing remote code execution.
2
How do I fix CVE-2014-9240?
To fix CVE-2014-9240, upgrade MyBB to version 1.8.2 or later.
3
What versions of MyBB are affected by CVE-2014-9240?
CVE-2014-9240 affects MyBB versions 1.8.0 and 1.8.1.
4
What is the nature of the attack in CVE-2014-9240?
CVE-2014-9240 allows attackers to execute arbitrary SQL commands via the question_id parameter.
5
What component of MyBB is vulnerable in CVE-2014-9240?
The member.php file in MyBB is the vulnerable component in CVE-2014-9240.