SQL injection vulnerability in usercp.php in MyBulletinBoard (MyBB) allows remote attackers to execute arbitrary SQL commands via the awayday parameter.
| Software | From | Fixed in |
|---|---|---|
| mybulletinboard / mybulletinboard | rc4 | rc4.x |
| mybulletinboard / mybulletinboard | 1.0_pr2 | 1.0_pr2.x |