The remote web server is running a PHP application that is vulnerable to multiple attack vectors.
Description
Versions of MyBB (MyBulletinBoard) prior to 1.6.10 are affected by the following vulnerabilities : - A SQL injection vulnerability exists due to improper sanitization of user-supplied input during database optimization. - A SQL injection vulnerability exists due to improper sanitization of user-supplied input when creating database backups. - A cross-site scripting vulnerability (XSS) exists due to improper validation of user-supplied input passed via theme names. - An information disclosure vulnerability exists due to improper verification of permissions for forums where a user can only see their own threads. - A cross-site scripting vulnerability exists due to improper validation of user-supplied input passed via the debug page. - An unspecified vulnerability exists due to improper validation of user-supplied input in 'modcp.php'. - An unspecified vulnerability exists due to improper validation of user-supplied input in 'calendar.php'.