CVE-2013-6936
MyBB Ajax forum stat Plugin 2.0 - SQL Injection via tooltip or usertooltip Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2013-6936. PoCs published by IeDb ir.
AI-analyzed exploit summary This exploit demonstrates SQL injection vulnerabilities in the MyBB Ajaxfs plugin via the 'tooltip' and 'usertooltip' GET parameters. The PoC shows how unvalidated input can lead to SQL syntax errors, confirming the vulnerability.
Description
Multiple SQL injection vulnerabilities in ajaxfs.php in the Ajax forum stat (Ajaxfs) Plugin 2.0 for MyBB (aka MyBulletinBoard) allow remote attackers to execute arbitrary SQL commands via the (1) tooltip or (2) usertooltip parameter.
Exploits (1)
This exploit demonstrates SQL injection vulnerabilities in the MyBB Ajaxfs plugin via the 'tooltip' and 'usertooltip' GET parameters. The PoC shows how unvalidated input can lead to SQL syntax errors, confirming the vulnerability.