Description
SQL injection vulnerability in the Group Promotions module in the admin control panel in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Remediation
References
Related Vulnerabilities
OpenVPN AS Resource Management Errors Vulnerability (CVE-2014-8104)
Oracle Database Server Other Vulnerability (CVE-2002-0840)
ownCloud Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-3835)
WordPress Plugin Velvet Blues Update URLs Unspecified Vulnerability (2.1)
WordPress Plugin Login No Captcha reCAPTCHA Security Bypass (1.6.11)