CVE-2005-4199

Multiple SQL injection vulnerabilities in MyBulletinBoard (MyBB) before 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) month, (2) day, and (3) year parameters in an addevent action in calendar.php; (4) threadmode and (5) showcodebuttons in an options action in usercp.php; (6) list parameter in an editlists action to usercp.php; (7) rating parameter in a rate action in member.php; and (8) rating parameter in either showthread.php or ratethread.php.
References
Link Resource
http://archives.neohapsis.com/archives/fulldisclosure/2005-12/0379.html
http://community.mybboard.net/showthread.php?tid=5184&pid=30964#pid30964
http://secunia.com/advisories/18000 Patch Vendor Advisory
http://securityreason.com/securityalert/246
http://securityreason.com/securityalert/294
http://securitytracker.com/id?1015407
http://www.osvdb.org/22156
http://www.osvdb.org/22157
http://www.osvdb.org/22158
http://www.securityfocus.com/archive/1/419067/100/0/threaded
http://www.securityfocus.com/archive/1/420159/100/0/threaded
http://www.securityfocus.com/bid/15793 Patch
http://www.trapkit.de/advisories/TKADV2005-12-001.txt
http://www.trapkit.de/advisories/TKPN2005-12-001.txt Patch
http://www.vupen.com/english/advisories/2005/2842 Vendor Advisory
http://archives.neohapsis.com/archives/fulldisclosure/2005-12/0379.html
http://community.mybboard.net/showthread.php?tid=5184&pid=30964#pid30964
http://secunia.com/advisories/18000 Patch Vendor Advisory
http://securityreason.com/securityalert/246
http://securityreason.com/securityalert/294
http://securitytracker.com/id?1015407
http://www.osvdb.org/22156
http://www.osvdb.org/22157
http://www.osvdb.org/22158
http://www.securityfocus.com/archive/1/419067/100/0/threaded
http://www.securityfocus.com/archive/1/420159/100/0/threaded
http://www.securityfocus.com/bid/15793 Patch
http://www.trapkit.de/advisories/TKADV2005-12-001.txt
http://www.trapkit.de/advisories/TKPN2005-12-001.txt Patch
http://www.vupen.com/english/advisories/2005/2842 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mybb:mybb:*:pr2:*:*:*:*:*:*
cpe:2.3:a:mybb:mybb:1.0:beta4:*:*:*:*:*:*
cpe:2.3:a:mybb:mybb:1.0:pr1:*:*:*:*:*:*
cpe:2.3:a:mybb:mybb:1.0:rc1:*:*:*:*:*:*
cpe:2.3:a:mybb:mybb:1.0:rc2:*:*:*:*:*:*
cpe:2.3:a:mybb:mybb:1.0:rc3:*:*:*:*:*:*
cpe:2.3:a:mybb:mybb:1.0:rc4:*:*:*:*:*:*

History

21 Nov 2024, 00:03

Type Values Removed Values Added
References () http://archives.neohapsis.com/archives/fulldisclosure/2005-12/0379.html - () http://archives.neohapsis.com/archives/fulldisclosure/2005-12/0379.html -
References () http://community.mybboard.net/showthread.php?tid=5184&pid=30964#pid30964 - () http://community.mybboard.net/showthread.php?tid=5184&pid=30964#pid30964 -
References () http://secunia.com/advisories/18000 - Patch, Vendor Advisory () http://secunia.com/advisories/18000 - Patch, Vendor Advisory
References () http://securityreason.com/securityalert/246 - () http://securityreason.com/securityalert/246 -
References () http://securityreason.com/securityalert/294 - () http://securityreason.com/securityalert/294 -
References () http://securitytracker.com/id?1015407 - () http://securitytracker.com/id?1015407 -
References () http://www.osvdb.org/22156 - () http://www.osvdb.org/22156 -
References () http://www.osvdb.org/22157 - () http://www.osvdb.org/22157 -
References () http://www.osvdb.org/22158 - () http://www.osvdb.org/22158 -
References () http://www.securityfocus.com/archive/1/419067/100/0/threaded - () http://www.securityfocus.com/archive/1/419067/100/0/threaded -
References () http://www.securityfocus.com/archive/1/420159/100/0/threaded - () http://www.securityfocus.com/archive/1/420159/100/0/threaded -
References () http://www.securityfocus.com/bid/15793 - Patch () http://www.securityfocus.com/bid/15793 - Patch
References () http://www.trapkit.de/advisories/TKADV2005-12-001.txt - () http://www.trapkit.de/advisories/TKADV2005-12-001.txt -
References () http://www.trapkit.de/advisories/TKPN2005-12-001.txt - Patch () http://www.trapkit.de/advisories/TKPN2005-12-001.txt - Patch
References () http://www.vupen.com/english/advisories/2005/2842 - Vendor Advisory () http://www.vupen.com/english/advisories/2005/2842 - Vendor Advisory

Information

Published : 2005-12-13 11:03

Updated : 2024-11-21 00:03


NVD link : CVE-2005-4199

Mitre link : CVE-2005-4199

CVE.ORG link : CVE-2005-4199


JSON object : View

Products Affected

mybb

  • mybb
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')