Unrated severityNVD Advisory· Published Jan 16, 2006· Updated Apr 16, 2026
CVE-2006-0219
CVE-2006-0219
Description
The original distribution of MyBulletinBoard (MyBB) to update from older versions to 1.0.2 omits or includes older versions of certain critical files, which allows attackers to conduct (1) SQL injection attacks via an attachment name that is not properly handled by inc/functions_upload.php (CVE-2005-4602), and possibly (2) other attacks related to threadmode in usercp.php.
Affected products
4cpe:2.3:a:mybulletinboard:mybulletinboard:1.01:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:mybulletinboard:mybulletinboard:1.01:*:*:*:*:*:*:*
- cpe:2.3:a:mybulletinboard:mybulletinboard:1.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:mybulletinboard:mybulletinboard:1.0_final:*:*:*:*:*:*:*
- cpe:2.3:a:mybulletinboard:mybulletinboard:1.0_preview_release_2:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5News mentions
0No linked articles in our index yet.