High
CVSS 7.5
Overview
SQL injection vulnerability in inc/function_upload.php in MyBB before 1.0.1 allows remote attackers to execute arbitrary SQL commands via the file extension of an uploaded file attachment.
SQL injection vulnerability in inc/function_upload.php in MyBB before 1.0.1 allo...
SQL injection vulnerability in inc/function_upload.php in MyBB before 1.0.1 allows remote attackers to execute arbitrary SQL commands via the file extension of an uploaded file attachment.
This vulnerability is rated 🟠 HIGH.
Recommended actions: