MyBB Community Forums

Full Version: Possible SQL injection attempt?
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
Someone registered a used as: '.system(getenv(HTTP_J)).' which I'm pretty sure was an attempt at a SQL injection, though, I have know clue what it would do that would help them. It seems rather pointless to me.

See for yourself:
http://www.quate.net/board/member.php?ac...ile&uid=12

I'm running MyBB 1.1, and am about to upgrade to the latest.
http://community.mybboard.net/showthread.php?tid=9677

Also, see the announcement for the 1.1.3 release.