First published: Wed Dec 03 2014(Updated: )
SQL injection vulnerability in member.php in MyBB (aka MyBulletinBoard) 1.8.x before 1.8.2 allows remote attackers to execute arbitrary SQL commands via the question_id parameter in a do_register action.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MyBB | =1.8.0 | |
MyBB | =1.8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-9240 is classified as a critical SQL injection vulnerability allowing remote code execution.
To fix CVE-2014-9240, upgrade MyBB to version 1.8.2 or later.
CVE-2014-9240 affects MyBB versions 1.8.0 and 1.8.1.
CVE-2014-9240 allows attackers to execute arbitrary SQL commands via the question_id parameter.
The member.php file in MyBB is the vulnerable component in CVE-2014-9240.