CVE-2009-2230

MyBB <1.4.7 - SQL Injection

Title source: llm

Description

SQL injection vulnerability in inc/datahandlers/user.php in MyBB (aka MyBulletinBoard) before 1.4.7 allows remote authenticated users to execute arbitrary SQL commands via the birthdayprivacy parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by The:Paradox · phpwebappsphp
https://www.exploit-db.com/exploits/9001

Scores

EPSS 0.0090
EPSS Percentile 75.8%

Details

CWE
CWE-89
Status published
Products (22)
mybulletinboard/mybulletinboard 1.0
mybulletinboard/mybulletinboard 1.0.1
mybulletinboard/mybulletinboard 1.0.2
mybulletinboard/mybulletinboard 1.0.3
mybulletinboard/mybulletinboard 1.0.4
mybulletinboard/mybulletinboard 1.1
mybulletinboard/mybulletinboard 1.1.2
mybulletinboard/mybulletinboard 1.1.3
mybulletinboard/mybulletinboard 1.1.4
mybulletinboard/mybulletinboard 1.1.5
... and 12 more
Published Jun 26, 2009
Tracked Since Feb 18, 2026