CVE Database
/

CVE-2006-2589

Back to search

CVE-2006-2589

Published: May 25, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

SQL injection vulnerability in rss.php in MyBB (aka MyBulletinBoard) 1.1.1 allows remote attackers to execute arbitrary SQL commands via the comma parameter. NOTE: it is not clear from the original report how this attack can succeed, since the demonstration URL uses a variable that is overwritten with static data in the extracted source code.

VendorProductVersions

n/a

n/a

affected
n/a

References

mybb-rss-sql-injection(28520)
vdb-entry
x_refsource_XF
952
third-party-advisory
x_refsource_SREASON

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now