Vulnerabilities > CVE-2006-2908 - Remote PHP Script Code Injection vulnerability in Mybulletinboard 1.1.2

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
mybulletinboard
exploit available

Summary

The domecode function in inc/functions_post.php in MyBulletinBoard (MyBB) 1.1.2, and possibly other versions, allows remote attackers to execute arbitrary PHP code via the username field, which is used in a preg_replace function call with a /e (executable) modifier.

Vulnerable Configurations

Part Description Count
Application
Mybulletinboard
1

Exploit-Db

descriptionMyBulletinBoard (MyBB) < 1.1.3 Remote Code Execution Exploit. CVE-2006-2908. Webapps exploit for php platform
idEDB-ID:1909
last seen2016-01-31
modified2006-06-13
published2006-06-13
reporterJavier Olascoaga
sourcehttps://www.exploit-db.com/download/1909/
titleMyBulletinBoard MyBB < 1.1.3 - Remote Code Execution Exploit

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/47417/mybibi_pl.txt
idPACKETSTORM:47417
last seen2016-12-05
published2006-06-15
reporterJavier Olascoaga
sourcehttps://packetstormsecurity.com/files/47417/mybibi_pl.txt.html
titlemybibi_pl.txt