6.5
CVSSv2

CVE-2008-0787

Published: 15/02/2008 Updated: 15/10/2018
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in inc/datahandlers/pm.php in MyBB prior to 1.2.12 allows remote authenticated users to execute arbitrary SQL commands via the options[disablesmilies] parameter to private.php.

Vulnerable Product Search on Vulmon Subscribe to Product

mybulletinboard mybulletinboard 1.0.2

mybulletinboard mybulletinboard 1.0.3

mybulletinboard mybulletinboard 1.1.4

mybulletinboard mybulletinboard 1.1.5

mybulletinboard mybulletinboard 1.2.11

mybulletinboard mybulletinboard 1.2.3

mybulletinboard mybulletinboard 1.0

mybulletinboard mybulletinboard 1.0.1

mybulletinboard mybulletinboard 1.1.2

mybulletinboard mybulletinboard 1.1.3

mybulletinboard mybulletinboard 1.2

mybulletinboard mybulletinboard 1.2.10

mybulletinboard mybulletinboard 1.1

mybulletinboard mybulletinboard 1.1.1

mybulletinboard mybulletinboard 1.1.8

mybulletinboard mybulletinboard 1.10

mybulletinboard mybulletinboard rc3

mybulletinboard mybulletinboard rc4

mybulletinboard mybulletinboard 1.0.4

mybulletinboard mybulletinboard 1.0_pr2

mybulletinboard mybulletinboard 1.1.6

mybulletinboard mybulletinboard 1.1.7

mybulletinboard mybulletinboard 1.2.5

mybulletinboard mybulletinboard rc1

mybulletinboard mybulletinboard rc2

Exploits

#!/usr/bin/perl # # MyBB <=1211 SQL Injection Exploit based on wwwwaraxeus/advisory-64html # # Needs MySQL >=41 and a valid registration # # By F # use IO::Socket; use LWP::UserAgent; use HTTP::Cookies; use HTML::Entities; #### print("\n"); print("############################################################################ ...