CVE Vulnerabilities

CVE-2005-4602

Published: Dec 31, 2005 | Modified: Oct 19, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

SQL injection vulnerability in inc/function_upload.php in MyBB before 1.0.1 allows remote attackers to execute arbitrary SQL commands via the file extension of an uploaded file attachment.

Affected Software

Name Vendor Start Version End Version
Mybulletinboard Mybulletinboard 1.0_pr2 (including) 1.0_pr2 (including)
Mybulletinboard Mybulletinboard 1.00_rc1 (including) 1.00_rc1 (including)
Mybulletinboard Mybulletinboard 1.00_rc2 (including) 1.00_rc2 (including)
Mybulletinboard Mybulletinboard 1.00_rc3 (including) 1.00_rc3 (including)
Mybulletinboard Mybulletinboard 1.0_rc4 (including) 1.0_rc4 (including)
Mybulletinboard Mybulletinboard 1.00_rc4 (including) 1.00_rc4 (including)
Mybulletinboard Mybulletinboard 1.00_rc4_security_patch (including) 1.00_rc4_security_patch (including)
Mybulletinboard Mybulletinboard rc1 (including) rc1 (including)
Mybulletinboard Mybulletinboard rc2 (including) rc2 (including)
Mybulletinboard Mybulletinboard rc3 (including) rc3 (including)
Mybulletinboard Mybulletinboard rc4 (including) rc4 (including)

References