CVE-2007-2212
MyBB <= 1.2.5 - SQL Injection via Calendar Year or Month Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-2212. PoCs published by 0x86.
AI-analyzed exploit summary This exploit targets a SQL injection vulnerability in MyBulletinBoard (MyBB) <= 1.2.5 via the calendar.php script. It brute-forces the MD5 password hash of a specified user by leveraging a time-based blind SQL injection technique.
Description
Multiple SQL injection vulnerabilities in calendar.php in MyBB (aka MyBulletinBoard) 1.2.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) year or (2) month parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Exploits (1)
This exploit targets a SQL injection vulnerability in MyBulletinBoard (MyBB) <= 1.2.5 via the calendar.php script. It brute-forces the MD5 password hash of a specified user by leveraging a time-based blind SQL injection technique.