AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2006-1912

MEDIUM · CVSS 5.8 EPSS 1.60%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2006-04-20 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2006-1912
Severity
MEDIUM
CVSS
5.8
EPSS
1.60%

Original NVD Description

MyBB (MyBulletinBoard) 1.1.0 does not set the constant KILL_GLOBAL variable in (1) global.php and (2) inc/init.php, which allows remote attackers to initialize arbitrary variables that are processed by an @extract command, which could then be leveraged to conduct cross-site scripting (XSS) or SQL injection attacks.