Unrated severityNVD Advisory· Published Jun 26, 2009· Updated Apr 23, 2026
CVE-2009-2230
CVE-2009-2230
Description
SQL injection vulnerability in inc/datahandlers/user.php in MyBB (aka MyBulletinBoard) before 1.4.7 allows remote authenticated users to execute arbitrary SQL commands via the birthdayprivacy parameter.
Affected products
22cpe:2.3:a:mybulletinboard:mybulletinboard:*:*:*:*:*:*:*:*+ 21 more
- cpe:2.3:a:mybulletinboard:mybulletinboard:*:*:*:*:*:*:*:*range: <=1.4.6
- cpe:2.3:a:mybulletinboard:mybulletinboard:1.0:*:*:*:*:*:*:*
- cpe:2.3:a:mybulletinboard:mybulletinboard:1.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:mybulletinboard:mybulletinboard:1.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:mybulletinboard:mybulletinboard:1.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:mybulletinboard:mybulletinboard:1.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:mybulletinboard:mybulletinboard:1.1:*:*:*:*:*:*:*
- cpe:2.3:a:mybulletinboard:mybulletinboard:1.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:mybulletinboard:mybulletinboard:1.1.3:*:*:*:*:*:*:*
- cpe:2.3:a:mybulletinboard:mybulletinboard:1.1.4:*:*:*:*:*:*:*
- cpe:2.3:a:mybulletinboard:mybulletinboard:1.1.5:*:*:*:*:*:*:*
- cpe:2.3:a:mybulletinboard:mybulletinboard:1.1.6:*:*:*:*:*:*:*
- cpe:2.3:a:mybulletinboard:mybulletinboard:1.1.7:*:*:*:*:*:*:*
- cpe:2.3:a:mybulletinboard:mybulletinboard:1.1.8:*:*:*:*:*:*:*
- cpe:2.3:a:mybulletinboard:mybulletinboard:1.2:*:*:*:*:*:*:*
- cpe:2.3:a:mybulletinboard:mybulletinboard:1.2.10:*:*:*:*:*:*:*
- cpe:2.3:a:mybulletinboard:mybulletinboard:1.2.11:*:*:*:*:*:*:*
- cpe:2.3:a:mybulletinboard:mybulletinboard:1.2.3:*:*:*:*:*:*:*
- cpe:2.3:a:mybulletinboard:mybulletinboard:1.2.5:*:*:*:*:*:*:*
- cpe:2.3:a:mybulletinboard:mybulletinboard:1.4.2:*:*:*:*:*:*:*
- cpe:2.3:a:mybulletinboard:mybulletinboard:1.4.3:*:*:*:*:*:*:*
- cpe:2.3:a:mybulletinboard:mybulletinboard:1.4.5:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- blog.mybboard.net/2009/06/15/mybb-147-released-security-update/nvdPatch
- mybboard.net/download/104nvdPatch
- www.vupen.com/english/advisories/2009/1653nvdPatchVendor Advisory
- www.securityfocus.com/bid/35458nvdExploitPatch
- secunia.com/advisories/35517nvdVendor Advisory
- www.exploit-db.com/exploits/9001nvd
News mentions
0No linked articles in our index yet.