Record summary

CVE-2013-6936 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.

Description

Multiple SQL injection vulnerabilities in ajaxfs.php in the Ajax forum stat (Ajaxfs) Plugin 2.0 for MyBB (aka MyBulletinBoard) allow remote attackers to execute arbitrary SQL commands via the (1) tooltip or (2) usertooltip parameter.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBMyBB Ajaxfs 2 Plugin - SQL InjectionExploitDB exploitby IeDb irNot analyzed1 file
ExploitDB

PoC details

References

7