CVE-2015-8974: SQL Injection
Published Jan 31, 2017
·Updated
SQL injection vulnerability in the Group Promotions module in the admin control panel in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Affected Software
8 affected components
MyBB Merge System<=1.8.5
MyBB MyBB<=1.6.17
MyBB MyBB=1.8.0
MyBB MyBB=1.8.1
MyBB MyBB=1.8.2
MyBB MyBB=1.8.3
MyBB MyBB=1.8.4
MyBB MyBB=1.8.5
Event History
Jan 31, 2017
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Data Sourced
via NVD·10:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2015-8974?
CVE-2015-8974 is classified as a high severity SQL injection vulnerability.
2
How do I fix CVE-2015-8974?
To fix CVE-2015-8974, upgrade MyBB to version 1.6.18 or 1.8.6 or later.
3
What versions of MyBB are affected by CVE-2015-8974?
Versions of MyBB before 1.6.18 and all versions in the 1.8.x series prior to 1.8.6 are affected by CVE-2015-8974.
4
Can CVE-2015-8974 be exploited remotely?
Yes, CVE-2015-8974 allows remote attackers to execute arbitrary SQL commands.
5
What module in MyBB is affected by CVE-2015-8974?
The Group Promotions module in the admin control panel of MyBB is affected by CVE-2015-8974.