Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-0787. PoCs published by F.
AI-analyzed exploit summary This exploit targets a SQL injection vulnerability in MyBB <=1.2.11 by leveraging authenticated private message functionality to extract user credentials and other sensitive data from the database. It requires valid user credentials and constructs a malicious payload to exfiltrate data via the private messaging system.
Description
SQL injection vulnerability in inc/datahandlers/pm.php in MyBB before 1.2.12 allows remote authenticated users to execute arbitrary SQL commands via the options[disablesmilies] parameter to private.php.
Exploits (1)
This exploit targets a SQL injection vulnerability in MyBB <=1.2.11 by leveraging authenticated private message functionality to extract user credentials and other sensitive data from the database. It requires valid user credentials and constructs a malicious payload to exfiltrate data via the private messaging system.