CVE-2013-6936

Multiple SQL injection vulnerabilities in ajaxfs.php in the Ajax forum stat (Ajaxfs) Plugin 2.0 for MyBB (aka MyBulletinBoard) allow remote attackers to execute arbitrary SQL commands via the (1) tooltip or (2) usertooltip parameter.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:mybb:ajax_forum_stat:2.0:-:*:*:*:mybb:*:*

Information

Published : 2013-12-04 10:56

Updated : 2017-08-28 18:34


NVD link : CVE-2013-6936

Mitre link : CVE-2013-6936


JSON object : View

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Advertisement

dedicated server usa

Products Affected

mybb

  • ajax_forum_stat