CVE detail
CVE-2013-6936 — CVE-2013-6936
Published 2013-12-04 · Modified 2026-06-17 · Vendor mybb · Product ajax_forum_stat · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0248
EPSS probability
exploitation probability, 30d
83.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Multiple SQL injection vulnerabilities in ajaxfs.php in the Ajax forum stat (Ajaxfs) Plugin 2.0 for MyBB (aka MyBulletinBoard) allow remote attackers to execute arbitrary SQL commands via the (1) tooltip or (2) usertooltip parameter.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References