Security Advisory

CVE-2006-2589

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2006-05-25 10:00:00
Last updated 2024-08-07 17:58:51
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

SQL injection vulnerability in rss.php in MyBB (aka MyBulletinBoard) 1.1.1 allows remote attackers to execute arbitrary SQL commands via the comma parameter. NOTE: it is not clear from the original report how this attack can succeed, since the demonstration URL uses a variable that is overwritten with static data in the extracted source code.