← Vulnerability feed

Vulnerability record · CVE-2006-3775 · published 24 July 2006

CVE-2006-3775: Mybulletinboard sql injection vulnerability

Mybulletinboard · Mybulletinboard

SQL injection vulnerability in the init function in class_session.php in MyBB (aka MyBulletinBoard) 1.1.5 allows remote attackers to execute arbitrary SQL commands via the CLIENT-IP HTTP header ($_SERVER['HTTP_CLIENT_IP'] variable), as utilized by index.php.

7.5 CVSS 2.0 High EPSS 2.5% · top 16.0% CWE-89 · SQL injection
7.5CVSS 2.0 base score
2.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
14References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

SQL injection vulnerability in the init function in class_session.php in MyBB (aka MyBulletinBoard) 1.1.5 allows remote attackers to execute arbitrary SQL commands via the CLIENT-IP HTTP header ($_SERVER['HTTP_CLIENT_IP'] variable), as utilized by index.php.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2006-3775 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2005-4200Mybulletinboard vulnerabilityMultiple unspecified vulnerabilities in MyBulletinBoard (MyBB) before 1.0 have unknown impact and attack vectors, a different set of vulnerabilities …EPSS 2.2%7.5CVE-2009-2230Mybulletinboard sql injection vulnerabilitySQL injection vulnerability in inc/datahandlers/user.php in MyBB (aka MyBulletinBoard) before 1.4.7 allows remote authenticated users to execute arbi…EPSS 1.2%7.5CVE-2008-0382Mybulletinboard code injection vulnerabilityMultiple eval injection vulnerabilities in MyBB 1.2.10 and earlier allow remote attackers to execute arbitrary code via the sortby parameter to (1) f…EPSS 42%7.5CVE-2007-2211Mybulletinboard vulnerabilitySQL injection vulnerability in calendar.php in MyBB (aka MyBulletinBoard) 1.2.5 and earlier allows remote attackers to execute arbitrary SQL commands…EPSS 1.1%7.5CVE-2007-1963Mybb vulnerabilitySQL injection vulnerability in the create_session function in class_session.php in MyBB (aka MyBulletinBoard) 1.2.3 and earlier allows remote attacke…EPSS 1.3%7.5CVE-2006-3758Mybulletinboard vulnerabilityinc/init.php in Archive Mode (Light) in MyBB (aka MyBulletinBoard) 1.1.4 calls the extract function with EXTR_OVERWRITE on HTTP POST and GET variable…EPSS 1.3%7.5CVE-2006-3760Mybulletinboard vulnerabilityMultiple SQL injection vulnerabilities in MyBB (aka MyBulletinBoard) 1.1.4 allow remote attackers to execute arbitrary SQL commands via unspecified v…EPSS 1.2%7.5CVE-2006-3420Mybulletinboard vulnerabilityCross-site request forgery (CSRF) vulnerability in editpost.php in MyBulletinBoard (MyBB) before 1.1.5 allows remote attackers to perform unauthorize…EPSS 1.5%

Source: NIST National Vulnerability Database (record CVE-2006-3775), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.