VYPR
Unrated severityNVD Advisory· Published Dec 31, 2014· Updated May 6, 2026

CVE-2014-9254

CVE-2014-9254

Description

bb_func_unsub.php in MiniBB 3.1 before 20141127 uses an incorrect regular expression, which allows remote attackers to conduct SQl injection attacks via the code parameter in an unsubscribe action to index.php.

Affected products

1
  • cpe:2.3:a:minibb:minibb:*:*:*:*:*:*:*:*
    Range: <=3.1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.