← Vulnerability feed

Vulnerability record · CVE-2008-0382 · published 22 January 2008

CVE-2008-0382: Mybulletinboard code injection vulnerability

Mybulletinboard · Mybulletinboard

Multiple eval injection vulnerabilities in MyBB 1.2.10 and earlier allow remote attackers to execute arbitrary code via the sortby parameter to (1) forumdisplay.php or (2) a results action in search.php.

7.5 CVSS 2.0 High EPSS 42% · top 1.4% CWE-94 · Code injection
7.5CVSS 2.0 base score
42%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References
16 Jun 2026Last modified by NVD

Description

Multiple eval injection vulnerabilities in MyBB 1.2.10 and earlier allow remote attackers to execute arbitrary code via the sortby parameter to (1) forumdisplay.php or (2) a results action in search.php.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-0382 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2005-4200Mybulletinboard vulnerabilityMultiple unspecified vulnerabilities in MyBulletinBoard (MyBB) before 1.0 have unknown impact and attack vectors, a different set of vulnerabilities …EPSS 2.2%7.5CVE-2009-2230Mybulletinboard sql injection vulnerabilitySQL injection vulnerability in inc/datahandlers/user.php in MyBB (aka MyBulletinBoard) before 1.4.7 allows remote authenticated users to execute arbi…EPSS 1.2%7.5CVE-2007-2211Mybulletinboard vulnerabilitySQL injection vulnerability in calendar.php in MyBB (aka MyBulletinBoard) 1.2.5 and earlier allows remote attackers to execute arbitrary SQL commands…EPSS 1.1%7.5CVE-2007-1963Mybb vulnerabilitySQL injection vulnerability in the create_session function in class_session.php in MyBB (aka MyBulletinBoard) 1.2.3 and earlier allows remote attacke…EPSS 1.3%7.5CVE-2006-3775Mybulletinboard sql injection vulnerabilitySQL injection vulnerability in the init function in class_session.php in MyBB (aka MyBulletinBoard) 1.1.5 allows remote attackers to execute arbitrar…EPSS 2.5%7.5CVE-2006-3758Mybulletinboard vulnerabilityinc/init.php in Archive Mode (Light) in MyBB (aka MyBulletinBoard) 1.1.4 calls the extract function with EXTR_OVERWRITE on HTTP POST and GET variable…EPSS 1.3%7.5CVE-2006-3760Mybulletinboard vulnerabilityMultiple SQL injection vulnerabilities in MyBB (aka MyBulletinBoard) 1.1.4 allow remote attackers to execute arbitrary SQL commands via unspecified v…EPSS 1.2%7.5CVE-2006-3420Mybulletinboard vulnerabilityCross-site request forgery (CSRF) vulnerability in editpost.php in MyBulletinBoard (MyBB) before 1.1.5 allows remote attackers to perform unauthorize…EPSS 1.5%

Source: NIST National Vulnerability Database (record CVE-2008-0382), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.