7.5
CVSSv2

CVE-2005-2580

Published: 16/08/2005 Updated: 18/10/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 770
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in MyBulletinBoard (MyBB) 1.00 RC4 with Security Patch allow remote malicious users to execute arbitrary SQL commands via the Username field in (1) index.php or (2) member.php, action parameter to (3) search.php or (4) member.php, or (5) polloptions parameter to polls.php.

Vulnerable Product Search on Vulmon Subscribe to Product

mybulletinboard mybulletinboard 1.00_rc4_security_patch

Exploits

source: wwwsecurityfocuscom/bid/14553/info MyBulletinBoard is prone to multiple SQL injection vulnerability These issues are due to a failure in the application to properly sanitize user-supplied input before using it in SQL queries Successful exploitation could result in a compromise of the application, disclosure or modification of ...
source: wwwsecurityfocuscom/bid/14553/info MyBulletinBoard is prone to multiple SQL injection vulnerability These issues are due to a failure in the application to properly sanitize user-supplied input before using it in SQL queries Successful exploitation could result in a compromise of the application, disclosure or modification of d ...
source: wwwsecurityfocuscom/bid/14553/info MyBulletinBoard is prone to multiple SQL injection vulnerability These issues are due to a failure in the application to properly sanitize user-supplied input before using it in SQL queries Successful exploitation could result in a compromise of the application, disclosure or modification ...
source: wwwsecurityfocuscom/bid/14553/info MyBulletinBoard is prone to multiple SQL injection vulnerability These issues are due to a failure in the application to properly sanitize user-supplied input before using it in SQL queries Successful exploitation could result in a compromise of the application, disclosure or modificatio ...