
CVE-2006-1345
https://notcve.org/view.php?id=CVE-2006-1345
22 Mar 2006 — polls.php in MyBB (aka MyBulletinBoard) 1.10 allows remote attackers to obtain sensitive information via a vote action with an "option[]=null" parameter value, which reveals the path in an error message. • http://www.securityfocus.com/archive/1/428056/100/0/threaded •

CVE-2006-1281
https://notcve.org/view.php?id=CVE-2006-1281
19 Mar 2006 — Cross-site scripting (XSS) vulnerability in member.php in MyBulletinBoard (MyBB) 1.04 allows remote attackers to inject arbitrary web script or HTML via the url parameter, a different vulnerability than CVE-2006-1272. NOTE: 1.10 was later reported to be vulnerable. • http://community.mybboard.net/showthread.php?tid=7368 •

CVE-2006-1282
https://notcve.org/view.php?id=CVE-2006-1282
19 Mar 2006 — CRLF injection vulnerability in inc/function.php in MyBulletinBoard (MyBB) 1.04 allows remote attackers to conduct cross-site scripting (XSS), poison caches, or hijack pages via CRLF (%0A%0D) sequences in the Referrer HTTP header field, possibly when redirecting to other web pages. • http://community.mybboard.net/showthread.php?tid=7368 •

CVE-2005-4602
https://notcve.org/view.php?id=CVE-2005-4602
31 Dec 2005 — SQL injection vulnerability in inc/function_upload.php in MyBB before 1.0.1 allows remote attackers to execute arbitrary SQL commands via the file extension of an uploaded file attachment. • http://secunia.com/advisories/18281 •

CVE-2005-4603
https://notcve.org/view.php?id=CVE-2005-4603
31 Dec 2005 — Cross-site scripting (XSS) vulnerability in printthread.php in MyBB 1.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via a thread message, which is not properly sanitized in the print view of the thread. • http://secunia.com/advisories/18281 •

CVE-2005-4200
https://notcve.org/view.php?id=CVE-2005-4200
13 Dec 2005 — Multiple unspecified vulnerabilities in MyBulletinBoard (MyBB) before 1.0 have unknown impact and attack vectors, a different set of vulnerabilities than those identified by CVE-2005-4199. • http://community.mybboard.net/showthread.php?tid=5184&pid=30964#pid30964 •

CVE-2005-3326 – MyBulletinBoard (MyBB) 1.0 - 'usercp.php' SQL Injection
https://notcve.org/view.php?id=CVE-2005-3326
27 Oct 2005 — SQL injection vulnerability in usercp.php in MyBulletinBoard (MyBB) allows remote attackers to execute arbitrary SQL commands via the awayday parameter. • https://www.exploit-db.com/exploits/26396 •