Unrated severityNVD Advisory· Published Feb 15, 2008· Updated Apr 23, 2026
CVE-2008-0787
CVE-2008-0787
Description
SQL injection vulnerability in inc/datahandlers/pm.php in MyBB before 1.2.12 allows remote authenticated users to execute arbitrary SQL commands via the options[disablesmilies] parameter to private.php.
Affected products
25cpe:2.3:a:mybulletinboard:mybulletinboard:1.0:*:*:*:*:*:*:*+ 24 more
- cpe:2.3:a:mybulletinboard:mybulletinboard:1.0:*:*:*:*:*:*:*
- cpe:2.3:a:mybulletinboard:mybulletinboard:1.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:mybulletinboard:mybulletinboard:1.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:mybulletinboard:mybulletinboard:1.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:mybulletinboard:mybulletinboard:1.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:mybulletinboard:mybulletinboard:1.0_pr2:*:*:*:*:*:*:*
- cpe:2.3:a:mybulletinboard:mybulletinboard:1.1:*:*:*:*:*:*:*
- cpe:2.3:a:mybulletinboard:mybulletinboard:1.10:*:*:*:*:*:*:*
- cpe:2.3:a:mybulletinboard:mybulletinboard:1.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:mybulletinboard:mybulletinboard:1.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:mybulletinboard:mybulletinboard:1.1.3:*:*:*:*:*:*:*
- cpe:2.3:a:mybulletinboard:mybulletinboard:1.1.4:*:*:*:*:*:*:*
- cpe:2.3:a:mybulletinboard:mybulletinboard:1.1.5:*:*:*:*:*:*:*
- cpe:2.3:a:mybulletinboard:mybulletinboard:1.1.6:*:*:*:*:*:*:*
- cpe:2.3:a:mybulletinboard:mybulletinboard:1.1.7:*:*:*:*:*:*:*
- cpe:2.3:a:mybulletinboard:mybulletinboard:1.1.8:*:*:*:*:*:*:*
- cpe:2.3:a:mybulletinboard:mybulletinboard:1.2:*:*:*:*:*:*:*
- cpe:2.3:a:mybulletinboard:mybulletinboard:1.2.10:*:*:*:*:*:*:*
- cpe:2.3:a:mybulletinboard:mybulletinboard:1.2.11:*:*:*:*:*:*:*
- cpe:2.3:a:mybulletinboard:mybulletinboard:1.2.3:*:*:*:*:*:*:*
- cpe:2.3:a:mybulletinboard:mybulletinboard:1.2.5:*:*:*:*:*:*:*
- cpe:2.3:a:mybulletinboard:mybulletinboard:rc1:*:*:*:*:*:*:*
- cpe:2.3:a:mybulletinboard:mybulletinboard:rc2:*:*:*:*:*:*:*
- cpe:2.3:a:mybulletinboard:mybulletinboard:rc3:*:*:*:*:*:*:*
- cpe:2.3:a:mybulletinboard:mybulletinboard:rc4:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- community.mybboard.net/showthread.phpnvdPatch
- www.securityfocus.com/bid/27378nvdExploitPatch
- www.waraxe.us/advisory-64.htmlnvdExploit
- secunia.com/advisories/28572/nvdVendor Advisory
- www.securityfocus.com/archive/1/486763/100/200/threadednvd
- www.securitytracker.com/idnvd
- www.vupen.com/english/advisories/2008/0238nvd
- www.exploit-db.com/exploits/5070nvd
News mentions
0No linked articles in our index yet.