CVE-2007-2211
MyBulletinBoard < 1.2.5 - SQL Injection via Calendar Day Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-2211. PoCs published by 0x86.
AI-analyzed exploit summary This exploit targets a SQL injection vulnerability in MyBulletinBoard (MyBB) <= 1.2.5 via the calendar.php script. It brute-forces the MD5 password hash of a specified user by leveraging a time-based blind SQL injection technique.
Description
SQL injection vulnerability in calendar.php in MyBB (aka MyBulletinBoard) 1.2.5 and earlier allows remote attackers to execute arbitrary SQL commands via the day parameter in a dayview action.
Exploits (1)
This exploit targets a SQL injection vulnerability in MyBulletinBoard (MyBB) <= 1.2.5 via the calendar.php script. It brute-forces the MD5 password hash of a specified user by leveraging a time-based blind SQL injection technique.