CVE-2015-8974
critical
CVSS v3
10.0
CVSS v2
7.5
VIR risk
10.0
Description
SQL injection vulnerability in the Group Promotions module in the admin control panel in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Predictions
Exploit likelihood
98%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cve@mitre.org — https://blog.mybb.com/2015/09/07/mybb-1-8-6-1-6-18-merge-system-1-8-6-release/
References
- http://www.openwall.com/lists/oss-security/2016/11/10/8
- http://www.openwall.com/lists/oss-security/2016/11/18/1
- http://www.securityfocus.com/bid/94397
- https://blog.mybb.com/2015/09/07/mybb-1-8-6-1-6-18-merge-system-1-8-6-release/
- http://www.openwall.com/lists/oss-security/2016/11/10/8
- http://www.openwall.com/lists/oss-security/2016/11/18/1
- http://www.securityfocus.com/bid/94397
- https://blog.mybb.com/2015/09/07/mybb-1-8-6-1-6-18-merge-system-1-8-6-release/
CWEs
CWE-89
Verify integrity in audit chain (admin only). AS-IS.