CVE-2006-3758
inc/init.php in Archive Mode (Light) in MyBB (aka MyBulletinBoard) 1.1.4 calls the extract function with EXTR_OVERWRITE on HTTP POST and GET variables, which allows remote attackers to overwrite arbitrary variables, as demonstrated via an SQL injection…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.34%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
inc/init.php in Archive Mode (Light) in MyBB (aka MyBulletinBoard) 1.1.4 calls the extract function with EXTR_OVERWRITE on HTTP POST and GET variables, which allows remote attackers to overwrite arbitrary variables, as demonstrated via an SQL injection using the _SERVER[HTTP_CLIENT_IP] parameter in archive/index.php.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.34% probability · 70th percentile
- CISA KEV
- Not listed
- Affected
- mybulletinboard/mybulletinboard
- Source
- cve@mitre.org
References
- http://community.mybboard.net/showthread.php?tid=10115
- http://myimei.com/security/2006-06-24/mybb104archive-modelight-parameter-extractionvarable-overwriting.html
- http://secunia.com/advisories/20873Patch, Vendor Advisory
- http://www.mybboard.com/archive.php?nid=15
- http://www.osvdb.org/26809
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27445
- http://community.mybboard.net/showthread.php?tid=10115
- http://myimei.com/security/2006-06-24/mybb104archive-modelight-parameter-extractionvarable-overwriting.html
- http://secunia.com/advisories/20873Patch, Vendor Advisory
- http://www.mybboard.com/archive.php?nid=15
- http://www.osvdb.org/26809
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27445
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.