7.5
CVSSv2

CVE-2009-2230

Published: 26/06/2009 Updated: 19/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in inc/datahandlers/user.php in MyBB (aka MyBulletinBoard) prior to 1.4.7 allows remote authenticated users to execute arbitrary SQL commands via the birthdayprivacy parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

mybulletinboard mybulletinboard 1.1

mybulletinboard mybulletinboard 1.1.7

mybulletinboard mybulletinboard 1.1.6

mybulletinboard mybulletinboard 1.0.3

mybulletinboard mybulletinboard 1.0.4

mybulletinboard mybulletinboard 1.2.10

mybulletinboard mybulletinboard 1.2.11

mybulletinboard mybulletinboard 1.1.2

mybulletinboard mybulletinboard 1.0

mybulletinboard mybulletinboard 1.4.5

mybulletinboard mybulletinboard

mybulletinboard mybulletinboard 1.1.3

mybulletinboard mybulletinboard 1.2

mybulletinboard mybulletinboard 1.1.5

mybulletinboard mybulletinboard 1.1.4

mybulletinboard mybulletinboard 1.4.2

mybulletinboard mybulletinboard 1.4.3

mybulletinboard mybulletinboard 1.2.3

mybulletinboard mybulletinboard 1.2.5

mybulletinboard mybulletinboard 1.1.8

mybulletinboard mybulletinboard 1.0.1

mybulletinboard mybulletinboard 1.0.2

Exploits

<?PHP /* Someone decided to contact mybb's staff informing about this vulnerability with the obvious result that this will not work anymore Fucking moron I'm releasing a non-finished version of the exploit No help, PoC and with the necessity of --admindir flag Going to update it in the next days For historical reason, i'm leaving the ori ...