CVE-2016-9402: SQL Injection
Published Jan 31, 2017
·Updated
SQL injection vulnerability in the moderation tool in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
Affected Software
2 affected components
MyBB Merge System<=1.8.6
MyBB MyBB<=1.8.6
Remediation
Patch Available
Patch Available
Event History
Jan 31, 2017
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Data Sourced
via NVD·10:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-9402?
CVE-2016-9402 is considered a high severity vulnerability due to its potential for remote SQL command execution.
2
How do I fix CVE-2016-9402?
To fix CVE-2016-9402, you should upgrade MyBB and MyBB Merge System to version 1.8.7 or later.
3
Which versions of MyBB are affected by CVE-2016-9402?
CVE-2016-9402 affects MyBB versions prior to 1.8.7, specifically versions 1.8.6 and earlier.
4
What type of vulnerability is CVE-2016-9402?
CVE-2016-9402 is classified as an SQL injection vulnerability in the moderation tool.
5
Can CVE-2016-9402 be exploited remotely?
Yes, CVE-2016-9402 can be exploited remotely, allowing attackers to execute arbitrary SQL commands.