Multiple SQL injection vulnerabilities in MyBulletinBoard (MyBB) before 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) month, (2) day, and (3) year parameters in an addevent action in calendar.php; (4) threadmode and (5) showcodebuttons in an options action in usercp.php; (6) list parameter in an editlists action to usercp.php; (7) rating parameter in a rate action in member.php; and (8) rating parameter in either showthread.php or ratethread.php.
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2005-12-13T11:00:00
Updated: 2018-10-19T14:57:01
Reserved: 2005-12-13T00:00:00
Link: CVE-2005-4199
JSON object: View
NVD Information
Status : Modified
Published: 2005-12-13T11:03:00.000
Modified: 2018-10-19T15:40:32.237
Link: CVE-2005-4199
JSON object: View
Redhat Information
No data.
CWE