Unrated severityNVD Advisory· Published Jan 22, 2008· Updated Apr 23, 2026
CVE-2008-0383
CVE-2008-0383
Description
Multiple SQL injection vulnerabilities in MyBB 1.2.10 and earlier allow remote moderators and administrators to execute arbitrary SQL commands via (1) the mergepost parameter in a do_mergeposts action, (2) rid parameter in an allreports action, or (3) threads parameter in a do_multimovethreads action to (a) moderation.php; or (4) gid parameter to (b) admin/usergroups.php.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- www.securityfocus.com/bid/27323nvdExploitPatch
- www.waraxe.us/advisory-62.htmlnvdExploit
- secunia.com/advisories/28509nvdVendor Advisory
- community.mybboard.net/showthread.phpnvd
- securityreason.com/securityalert/3558nvd
- www.securityfocus.com/archive/1/486433/100/0/threadednvd
- exchange.xforce.ibmcloud.com/vulnerabilities/39728nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/39729nvd
News mentions
0No linked articles in our index yet.