First published: Tue Jan 31 2017(Updated: )
SQL injection vulnerability in the Group Promotions module in the admin control panel in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MyBB | <=1.8.5 | |
MyBB | <=1.6.17 | |
MyBB | =1.8.0 | |
MyBB | =1.8.1 | |
MyBB | =1.8.2 | |
MyBB | =1.8.3 | |
MyBB | =1.8.4 | |
MyBB | =1.8.5 | |
<=1.8.5 | ||
<=1.6.17 | ||
=1.8.0 | ||
=1.8.1 | ||
=1.8.2 | ||
=1.8.3 | ||
=1.8.4 | ||
=1.8.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-8974 is classified as a high severity SQL injection vulnerability.
To fix CVE-2015-8974, upgrade MyBB to version 1.6.18 or 1.8.6 or later.
Versions of MyBB before 1.6.18 and all versions in the 1.8.x series prior to 1.8.6 are affected by CVE-2015-8974.
Yes, CVE-2015-8974 allows remote attackers to execute arbitrary SQL commands.
The Group Promotions module in the admin control panel of MyBB is affected by CVE-2015-8974.