SQL injection vulnerability in member.php in MyBulletinBoard (MyBB) allows remote attackers to execute arbitrary SQL statements via the fid parameter.
| Software | From | Fixed in |
|---|---|---|
| mybulletinboard / mybulletinboard | rc3 | rc3.x |
| mybulletinboard / mybulletinboard | rc2 | rc2.x |
| mybulletinboard / mybulletinboard | rc1 | rc1.x |
| mybulletinboard / mybulletinboard | rc4 | rc4.x |