Vulnerable Systems:
*Profile Wii Friend Code Plugin for MyBB 1.0
Profile Wii Friend Code Plugin for MyBB contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the profilewfc.php script not properly sanitizing user-supplied input to the 'Wii Friend Code' field. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
SQL Injection:
1. Go to your user cp and edit your profile - usercp.php?action=profile
2. Enter this into the Wii Friend Code field as you would do with the 1st vulnerability: x', usergroup='4
3. submit and now you belong to whatever usergroup to choice to belong to