Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The original distribution of MyBulletinBoard (MyBB) to update from older versions to 1.0.2 omits or includes older versions of certain critical files, which allows attackers to conduct (1) SQL injection attacks via an attachment name that is not properly handled by inc/functions_upload.php (CVE-2005-4602), and possibly (2) other attacks related to threadmode in usercp.php.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
MyBB Usercp.PHP SQL注入漏洞
Vulnerability Description
要从较旧版本更新到1.0.2版的MyBulletinBoard (MyBB)原始分发会省略或包含某些较旧版本的重要文件,这可让攻击者(1)通过未经inc/functions_upload.php适当处理的附件名称执行SQL注入攻击,还可能(2)执行与usercp.php中的线程模式相关的其他攻击。
CVSS Information
N/A
Vulnerability Type
N/A