[Forgot Password]
Login  Register Subscribe

23631

 
 

115083

 
 

97147

 
 

909

 
 

78730

 
 

109

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML

CVE-2009-4449

Date: (C)2009-12-29   (M)2015-12-16
 
CVSS Score: 6.3Access Vector: NETWORK
Exploitability Subscore: 6.8Access Complexity: MEDIUM
Impact Subscore: 6.9Authentication: SINGLE_INSTANCE
 Confidentiality: COMPLETE
 Integrity: NONE
 Availability: NONE











Directory traversal vulnerability in MyBB (aka MyBulletinBoard) 1.4.10, and possibly earlier versions, when changing the user avatar from the gallery, allows remote authenticated users to determine the existence of files via directory traversal sequences in the avatar and possibly the gallery parameters, related to (1) admin/modules/user/users.php and (2) usercp.php.

Reference:
BID-37489
SECUNIA-37906
OSVDB-61359
ADV-2009-3651
http://openwall.com/lists/oss-security/2010/10/08/7
http://openwall.com/lists/oss-security/2010/10/11/8
http://openwall.com/lists/oss-security/2010/12/06/2
http://blog.mybboard.net/2009/12/29/mybb-1-4-11-released-minor-patch-security-update/
http://dev.mybboard.net/issues/617
http://dev.mybboard.net/projects/mybb/repository/revisions/4663/diff/branches/1.4-stable/admin/modules/user/users.php
http://dev.mybboard.net/projects/mybb/repository/revisions/4663/diff/branches/1.4-stable/usercp.php

CPE    1
cpe:/a:mybboard:mybb:1.4.10
CWE    1
CWE-22

© 2013 SecPod Technologies