CVE-2016-9416: SQL Injection
Published Jan 31, 2017
·Updated
SQL injection vulnerability in the users data handler in MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Affected Software
2 affected components
MyBB Merge System<=1.8.7
MyBB MyBB<=1.8.7
Remediation
Patch Available
Patch Available
Event History
Jan 31, 2017
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Data Sourced
via NVD·10:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-9416?
CVE-2016-9416 is classified as a high severity SQL injection vulnerability.
2
How do I fix CVE-2016-9416?
To fix CVE-2016-9416, upgrade MyBB to version 1.8.8 or later.
3
What software is affected by CVE-2016-9416?
CVE-2016-9416 affects MyBB versions before 1.8.8 and the MyBB Merge System before 1.8.8.
4
What type of vulnerability is CVE-2016-9416?
CVE-2016-9416 is an SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands.
5
Are there known exploits for CVE-2016-9416?
Yes, there are known exploits that target CVE-2016-9416, taking advantage of the SQL injection flaw.