Korean
<< Back
VID 21832
Severity 30
Port 80, ...
Protocol TCP
Class CGI
Detailed Description The MyBulletinBoard program is vulnerable to multiple SQL injection vulnerabilities which exist in versions prior to 1.01. MyBulletinBoard is a freely available forum package developed in PHP and MYSQL. MyBulletinBoard versions prior to 1.01 could allow a remote attacker to execute arbitrary SQL commands, caused by improper filtering of user-supplied input passed to the 'mybbadmin' cookie in the 'admin/global.php' script and the file extension of uploaded files. These vulnerabilities could permit a remote attacker to pass malicious input to database queries, potentially resulting in data exposure, modification of the query logic, or even data modification or attacks against the database itself.

* References:
http://www.frsirt.com/english/advisories/2006/0012
http://www.osvdb.org/22159
http://secunia.com/advisories/18281
http://archives.neohapsis.com/archives/bugtraq/2005-12/0338.html

* Platforms Affected:
MyBB Group, MyBulletinBoard versions prior to 1.01
Any operating system Any version
Recommendation Upgrade to the latest version of MyBulletinBoard (1.01 or later), available from the MyBB Group Web site at http://www.mybboard.com
Related URL CVE-2005-4602 (CVE)
Related URL 16082,16097 (SecurityFocus)
Related URL 23936 (ISS)