Security Advisory

CVE-2008-0383

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2008-01-22 19:00:00
Last updated 2024-08-07 07:46:54
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Multiple SQL injection vulnerabilities in MyBB 1.2.10 and earlier allow remote moderators and administrators to execute arbitrary SQL commands via (1) the mergepost parameter in a do_mergeposts action, (2) rid parameter in an allreports action, or (3) threads parameter in a do_multimovethreads action to (a) moderation.php; or (4) gid parameter to (b) admin/usergroups.php.