Vulnerability Description
SQL injection vulnerability in member.php in MyBB (aka MyBulletinBoard) 1.8.x before 1.8.2 allows remote attackers to execute arbitrary SQL commands via the question_id parameter in a do_register action.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mybb | Mybb | 1.8.0 |
Related Weaknesses (CWE)
References
- http://blog.mybb.com/2014/11/13/mybb-1-8-2-released-security-release/PatchVendor Advisory
- http://packetstormsecurity.com/files/129109/MyBB-1.8.1-Cross-Site-Scripting-SQL-Exploit
- http://blog.mybb.com/2014/11/13/mybb-1-8-2-released-security-release/PatchVendor Advisory
- http://packetstormsecurity.com/files/129109/MyBB-1.8.1-Cross-Site-Scripting-SQL-Exploit
FAQ
What is CVE-2014-9240?
CVE-2014-9240 is a vulnerability with a CVSS score of 7.5 (HIGH). SQL injection vulnerability in member.php in MyBB (aka MyBulletinBoard) 1.8.x before 1.8.2 allows remote attackers to execute arbitrary SQL commands via the question_id parameter in a do_register acti...
How severe is CVE-2014-9240?
CVE-2014-9240 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-9240?
Check the references section above for vendor advisories and patch information. Affected products include: Mybb Mybb.