Description
** DISPUTED ** Multiple SQL injection vulnerabilities in MyBB (aka MyBulletinBoard) before 1.6.1 allow remote attackers to execute arbitrary SQL commands via the keywords parameter in a (1) do_search action to search.php or (2) do_stuff action to private.php. NOTE: the vendor disputes this issue, saying "Although this doesn't lead to an SQL injection, it does provide a general MyBB SQL error."
Remediation
References
Related Vulnerabilities
Internet Information Services Integer Overflow or Wraparound Vulnerability (CVE-2008-1446)
WordPress Plugin Ad Manager by WD-Advanced Ad Manager Multiple Vulnerabilities (1.0.11)
Joomla! Core 3.0.x Denial of Service (3.0.0 - 3.0.3)
WordPress Plugin ALO EasyMail Newsletter Multiple Vulnerabilities (2.6.00)