Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple SQL injection vulnerabilities in MyBulletinBoard (MyBB) before 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) month, (2) day, and (3) year parameters in an addevent action in calendar.php; (4) threadmode and (5) showcodebuttons in an options action in usercp.php; (6) list parameter in an editlists action to usercp.php; (7) rating parameter in a rate action in member.php; and (8) rating parameter in either showthread.php or ratethread.php.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
MyBB 多个SQL 注入漏洞
Vulnerability Description
在 MyBulletinBoard (MyBB) 1.0之前版本中的多个SQL注入漏洞,远程攻击者可以通过在calendar.php中的 addevent 操作中的 (1)月,(2) 日,和 (3)年参数;在 usercp.php 中的选项操作中 (4) threadmode 和 (5) showcodebuttons 参数;usercp.php的editlists操作中的(6) list参数;在member.php中rate操作中的(7) rating 参数; 和在showthread.php或rate
CVSS Information
N/A
Vulnerability Type
N/A