SQL injection vulnerability in inc/function_upload.php in MyBB before 1.0.1 allows remote attackers to execute arbitrary SQL commands via the file extension of an uploaded file attachment.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mybulletinboard | Mybulletinboard | 1.0_pr2 (including) | 1.0_pr2 (including) |
Mybulletinboard | Mybulletinboard | 1.00_rc1 (including) | 1.00_rc1 (including) |
Mybulletinboard | Mybulletinboard | 1.00_rc2 (including) | 1.00_rc2 (including) |
Mybulletinboard | Mybulletinboard | 1.00_rc3 (including) | 1.00_rc3 (including) |
Mybulletinboard | Mybulletinboard | 1.0_rc4 (including) | 1.0_rc4 (including) |
Mybulletinboard | Mybulletinboard | 1.00_rc4 (including) | 1.00_rc4 (including) |
Mybulletinboard | Mybulletinboard | 1.00_rc4_security_patch (including) | 1.00_rc4_security_patch (including) |
Mybulletinboard | Mybulletinboard | rc1 (including) | rc1 (including) |
Mybulletinboard | Mybulletinboard | rc2 (including) | rc2 (including) |
Mybulletinboard | Mybulletinboard | rc3 (including) | rc3 (including) |
Mybulletinboard | Mybulletinboard | rc4 (including) | rc4 (including) |