Unrated severityNVD Advisory· Published Mar 2, 2006· Updated Apr 16, 2026
CVE-2006-0959
CVE-2006-0959
Description
SQL injection vulnerability in misc.php in MyBulletinBoard (MyBB) 1.03, when register_globals is enabled, allows remote attackers to execute arbitrary SQL commands by setting the comma variable value via the comma parameter in a cookie. NOTE: 1.04 has also been reported to be affected.
Affected products
2cpe:2.3:a:mybulletinboard:mybulletinboard:1.0.3:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:mybulletinboard:mybulletinboard:1.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:mybulletinboard:mybulletinboard:1.0.4:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- secunia.com/advisories/19061nvdExploitVendor Advisory
- www.vupen.com/english/advisories/2006/0774nvdVendor Advisory
- securityreason.com/securityalert/512nvd
- www.osvdb.org/23554nvd
- www.securityfocus.com/archive/1/426320/100/0/threadednvd
- www.securityfocus.com/archive/1/426653/100/0/threadednvd
- www.securityfocus.com/bid/16631nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/24953nvd
- www.exploit-db.com/exploits/1539nvd
News mentions
0No linked articles in our index yet.