MyBB 1.1.1 Email Verification in User Activation SQL Injection Attack
SecurityAlert : 885 CVE : CVE-2006-2333 SecurityRisk : Medium (About) Remote Exploit : Yes Local Exploit : No Exploit Available : Yes Credit : addmimistrator gmail com Published : 13.05.2006
There is a security bug in MyBB 1.1.1 software (latest version fully
patched) that allows attacker performe a SQL Injection attack.
bug is in result of weak regullar expression for cheknig email and also
forgotting to addslash a value that entered in db and now fetch and
reinsert it.
MORE DETAILES IN ORIGINAL ADVISORY;)
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.