Sploitus

CVE-2006-3775

1 known exploit for CVE-2006-3775

SQL injection vulnerability in the init function in class_session.php in MyBB (aka MyBulletinBoard) 1.1.5 allows remote attackers to execute arbitrary SQL commands via the CLIENT-IP HTTP header ($_SERVER['HTTP_CLIENT_IP'] variable), as utilized by index.php.

Affected products
Mybb
Mybulletinboard
= 1.1.5
CVSS 2.0
7.5 HIGH
EPSS
2.4% (83th percentile)
Weakness
CWE-89
NVD status
Modified
Published
2006-07-21
CVE-2006-3775 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2006-3775

Proof-of-concept code and exploit modules indexed by Sploitus