CVE-2007-2212

MyBB <= 1.2.5 - SQL Injection via Calendar Year or Month Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-2212. PoCs published by 0x86.

AI-analyzed exploit summary This exploit targets a SQL injection vulnerability in MyBulletinBoard (MyBB) <= 1.2.5 via the calendar.php script. It brute-forces the MD5 password hash of a specified user by leveraging a time-based blind SQL injection technique.

Description

Multiple SQL injection vulnerabilities in calendar.php in MyBB (aka MyBulletinBoard) 1.2.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) year or (2) month parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Exploits (1)

exploitdb WORKING POC VERIFIED
by 0x86 · perlwebappsphp
https://www.exploit-db.com/exploits/3780

This exploit targets a SQL injection vulnerability in MyBulletinBoard (MyBB) <= 1.2.5 via the calendar.php script. It brute-forces the MD5 password hash of a specified user by leveraging a time-based blind SQL injection technique.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: MyBulletinBoard (MyBB) <= 1.2.5
No auth needed
Prerequisites: Target MyBB installation with vulnerable calendar.php script · Network access to the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/33814

Scores

EPSS 0.0091
EPSS Percentile 55.4%

Details

Status published
Products (1)
mybb/mybb 1.2.5
Published Apr 24, 2007
Tracked Since Feb 18, 2026