100030vdb entry
http://osvdb.org/100030 CVE-2013-6936
MyBB Ajaxfs 2 Plugin - SQL Injection
Record summary
CVE-2013-6936 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Multiple SQL injection vulnerabilities in ajaxfs.php in the Ajax forum stat (Ajaxfs) Plugin 2.0 for MyBB (aka MyBulletinBoard) allow remote attackers to execute arbitrary SQL commands via the (1) tooltip or (2) usertooltip parameter.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBMyBB Ajaxfs 2 Plugin - SQL InjectionExploitDB exploitby IeDb irNot analyzed1 file
References
7packetstormsecurity.com
http://packetstormsecurity.com/files/124091/MyBB-Ajaxfs-SQL-Injection.html 20131120 Mybb Ajaxfs Plugin Sql Injection vulnerabilitymailing list
http://seclists.org/bugtraq/2013/Nov/102 29797exploit
http://www.exploit-db.com/exploits/29797 iedb.ir
http://www.iedb.ir/exploits-889.html mybb-ajaxfs-sql-injection(89084)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/89084 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2013-6936