Description
SQL injection vulnerability in the Group Promotions module in the admin control panel in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Remediation
References
Related Vulnerabilities
Liferay Portal Improper Restriction of XML External Entity Reference Vulnerability (CVE-2024-25606)
WordPress MU 'wp-admin/wpmu-blogs.php' Multiple Cross-Site Scripting Vulnerabilities (1.0 - 2.5.1)
WordPress Plugin Simple Slide Show TimThumb Arbitrary File Upload (1.0)