CVE-2008-3070

MyBB < 1.2.12 - SQL Injection via User Language Variable

Title source: llm
STIX 2.1

Description

Unspecified vulnerability in inc/datahandler/user.php in MyBB before 1.2.13 has unknown impact and attack vectors related to the $user['language'] variable, probably related to SQL injection.

References (3)

Core 3
Core References
Various Sources x_refsource_confirm
http://community.mybboard.net/showthread.php?tid=31666
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/31013

Scores

EPSS 0.0088
EPSS Percentile 55.5%

Details

CWE
CWE-89
Status published
Products (1)
mybb/mybb < 1.2.12
Published Jul 08, 2008
Tracked Since Feb 18, 2026