CVE-2006-0219
The original distribution of MyBulletinBoard (MyBB) to update from older versions to 1.0.2 omits or includes older versions of certain critical files, which allows attackers to conduct (1) SQL injection attacks via an attachment name that is not…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.04%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The original distribution of MyBulletinBoard (MyBB) to update from older versions to 1.0.2 omits or includes older versions of certain critical files, which allows attackers to conduct (1) SQL injection attacks via an attachment name that is not properly handled by inc/functions_upload.php (CVE-2005-4602), and possibly (2) other attacks related to threadmode in usercp.php.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.04% probability · 62th percentile
- CISA KEV
- Not listed
- Affected
- mybulletinboard/mybulletinboard
- Source
- cve@mitre.org
References
- http://community.mybboard.net/showthread.php?tid=5853&pid=35088#pid35088
- http://community.mybboard.net/showthread.php?tid=5853&pid=35151#pid35151
- http://community.mybboard.net/showthread.php?tid=5960Patch
- http://www.securityfocus.com/bid/16230
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24115
- http://community.mybboard.net/showthread.php?tid=5853&pid=35088#pid35088
- http://community.mybboard.net/showthread.php?tid=5853&pid=35151#pid35151
- http://community.mybboard.net/showthread.php?tid=5960Patch
- http://www.securityfocus.com/bid/16230
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24115
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.