Skip to main content

Vendor archive

mybulletinboard CVEs

Beta · best-effort

63 CVEs tagged to vendor mybulletinboard1 Critical, 22 High, 37 Medium, 3 Low, 0 Unrated.

CVE-2009-2230

Published Jun 26, 2009

SQL injection vulnerability in inc/datahandlers/user.php in MyBB (aka MyBulletinBoard) before 1.4.7 allows remote authenticated users to execute arbitrary SQL commands via the bir…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0787

Published Feb 15, 2008

SQL injection vulnerability in inc/datahandlers/pm.php in MyBB before 1.2.12 allows remote authenticated users to execute arbitrary SQL commands via the options[disablesmilies] pa…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0382

Published Jan 22, 2008

Multiple eval injection vulnerabilities in MyBB 1.2.10 and earlier allow remote attackers to execute arbitrary code via the sortby parameter to (1) forumdisplay.php or (2) a resul…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-2211

Published Apr 24, 2007

SQL injection vulnerability in calendar.php in MyBB (aka MyBulletinBoard) 1.2.5 and earlier allows remote attackers to execute arbitrary SQL commands via the day parameter in a da…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-1963

Published Apr 11, 2007

SQL injection vulnerability in the create_session function in class_session.php in MyBB (aka MyBulletinBoard) 1.2.3 and earlier allows remote attackers to execute arbitrary SQL co…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-1964

Published Apr 11, 2007

member.php in MyBB (aka MyBulletinBoard), when debug mode is available, allows remote authenticated users to change the password of any account by providing the account's register…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4971

Published Sep 25, 2006

MyBB (aka MyBulletinBoard) allows remote attackers to obtain sensitive information via a direct request for inc/plugins/hello.php, which reveals the path in an error message.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4972

Published Sep 25, 2006

Cross-site scripting (XSS) vulnerability in archive/index.php/forum-4.html in MyBB (aka MyBulletinBoard) allows remote attackers to inject arbitrary web script or HTML via the nav…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4706

Published Sep 12, 2006

Cross-site scripting (XSS) vulnerability in inc/functions_post.php in MyBB (aka MyBulletinBoard) 1.1.7 allows remote attackers to inject arbitrary web script or HTML via a url BBC…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4707

Published Sep 12, 2006

Cross-site scripting (XSS) vulnerability in admin/global.php (aka the Admin CP login form) in MyBB (aka MyBulletinBoard) 1.1.7 allows remote attackers to inject arbitrary web scri…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4449

Published Aug 30, 2006

Cross-site scripting (XSS) vulnerability in attachment.php in MyBulletinBoard (MyBB) 1.1.7 and possibly other versions allows remote attackers to inject arbitrary web script or HT…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3953

Published Aug 1, 2006

Cross-site scripting (XSS) vulnerability in usercp.php in MyBB (aka MyBulletinBoard) 1.x allows remote attackers to inject arbitrary web script or HTML via the gallery parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3954

Published Aug 1, 2006

Directory traversal vulnerability in usercp.php in MyBB (aka MyBulletinBoard) 1.x allows remote attackers to read arbitrary files via a .. (dot dot) in the gallery parameter in a…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3775

Published Jul 24, 2006

SQL injection vulnerability in the init function in class_session.php in MyBB (aka MyBulletinBoard) 1.1.5 allows remote attackers to execute arbitrary SQL commands via the CLIENT-…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-3758

Published Jul 21, 2006

inc/init.php in Archive Mode (Light) in MyBB (aka MyBulletinBoard) 1.1.4 calls the extract function with EXTR_OVERWRITE on HTTP POST and GET variables, which allows remote attacke…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-3759

Published Jul 21, 2006

Unspecified vulnerability in MyBB (aka MyBulletinBoard) 1.1.4, related has unspecified impact and attack vectors related to "user group manipulation."

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3760

Published Jul 21, 2006

Multiple SQL injection vulnerabilities in MyBB (aka MyBulletinBoard) 1.1.4 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-3761

Published Jul 21, 2006

Cross-site scripting (XSS) vulnerability in inc/functions_post.php in MyBB (aka MyBulletinBoard) 1.0 RC2 through 1.1.4 allows remote attackers to inject arbitrary web script or HT…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3420

Published Jul 7, 2006

Cross-site request forgery (CSRF) vulnerability in editpost.php in MyBulletinBoard (MyBB) before 1.1.5 allows remote attackers to perform unauthorized actions as a logged in user…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-3243

Published Jun 27, 2006

SQL injection vulnerability in usercp.php in MyBB (MyBulletinBoard) 1.0 through 1.1.3 allows remote attackers to execute arbitrary SQL commands via the showcodebuttons parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-2908

Published Jun 13, 2006

The domecode function in inc/functions_post.php in MyBulletinBoard (MyBB) 1.1.2, and possibly other versions, allows remote attackers to execute arbitrary PHP code via the usernam…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-2949

Published Jun 12, 2006

Cross-site scripting (XSS) vulnerability in private.php in MyBB 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the do parameter.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-2589

Published May 25, 2006

SQL injection vulnerability in rss.php in MyBB (aka MyBulletinBoard) 1.1.1 allows remote attackers to execute arbitrary SQL commands via the comma parameter. NOTE: it is not clea…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-2333

Published May 12, 2006

Multiple SQL injection vulnerabilities in MyBB (aka MyBulletinBoard) 1.1.1 allow remote attackers to execute arbitrary SQL commands via the e-mail address when registering for a f…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-2336

Published May 12, 2006

SQL injection vulnerability in showthread.php in MyBB (aka MyBulletinBoard) 1.1.1 allows remote attackers to execute arbitrary SQL commands via the comma parameter.

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 63 CVEsPage 1 of 3