Unrated severityNVD Advisory· Published Jul 21, 2006· Updated Apr 16, 2026
CVE-2006-3758
CVE-2006-3758
Description
inc/init.php in Archive Mode (Light) in MyBB (aka MyBulletinBoard) 1.1.4 calls the extract function with EXTR_OVERWRITE on HTTP POST and GET variables, which allows remote attackers to overwrite arbitrary variables, as demonstrated via an SQL injection using the _SERVER[HTTP_CLIENT_IP] parameter in archive/index.php.
Affected products
1- cpe:2.3:a:mybulletinboard:mybulletinboard:1.1.4:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- secunia.com/advisories/20873nvdPatchVendor Advisory
- community.mybboard.net/showthread.phpnvd
- myimei.com/security/2006-06-24/mybb104archive-modelight-parameter-extractionvarable-overwriting.htmlnvd
- www.mybboard.com/archive.phpnvd
- www.osvdb.org/26809nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/27445nvd
News mentions
0No linked articles in our index yet.