CVE-2013-6936
Published Dec 4, 2013
Last updated 7 years ago
Overview
- Description
- Multiple SQL injection vulnerabilities in ajaxfs.php in the Ajax forum stat (Ajaxfs) Plugin 2.0 for MyBB (aka MyBulletinBoard) allow remote attackers to execute arbitrary SQL commands via the (1) tooltip or (2) usertooltip parameter.
- Source
- cve@mitre.org
- NVD status
- Modified
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 6.4
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-89
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:mybb:ajax_forum_stat:2.0:-:*:*:*:mybb:*:*", "vulnerable": true, "matchCriteriaId": "6C256D31-0385-47E7-97AE-47CE2B77B82D" } ], "operator": "OR" } ] } ]