CVE-2008-0383
MyBB < 1.2.10 - Authenticated SQL Injection via Moderation and Admin Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-0383. PoCs published by waraxe.
AI-analyzed exploit summary The exploit demonstrates SQL injection vulnerabilities in MyBB versions prior to 1.2.11. It includes multiple attack vectors via the 'moderation.php' endpoint, allowing unauthorized data access or manipulation.
Description
Multiple SQL injection vulnerabilities in MyBB 1.2.10 and earlier allow remote moderators and administrators to execute arbitrary SQL commands via (1) the mergepost parameter in a do_mergeposts action, (2) rid parameter in an allreports action, or (3) threads parameter in a do_multimovethreads action to (a) moderation.php; or (4) gid parameter to (b) admin/usergroups.php.
Exploits (1)
The exploit demonstrates SQL injection vulnerabilities in MyBB versions prior to 1.2.11. It includes multiple attack vectors via the 'moderation.php' endpoint, allowing unauthorized data access or manipulation.