Back

CVE-2006-0959

SQL injection vulnerability in misc.php in MyBulletinBoard (MyBB) 1.03, when register_globals is enabled, allows remote attackers to execute arbitrary SQL commands by setting the comma variable value via the comma parameter in a cookie. NOTE: 1.04 has also been reported to be affected.

Published: Mar 2, 2006 Modified: Jun 16, 2026
CWE-89

CVSS Metrics

Affected Products (2)

Vendor Product Version
mybulletinboard mybulletinboard 1.0.3
mybulletinboard mybulletinboard 1.0.4

GitHub Security Advisory GHSA-g8m6-2768-5rf4

SQL injection vulnerability in misc.php in MyBulletinBoard (MyBB) 1.03, when register_globals is...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 3.83%

Top 11% most likely to be exploited

Threat Score 31.1 / 100

Data Sources

NVD EPSS GitHub