[Forgot Password]
Login  Register Subscribe

23631

 
 

126951

 
 

99536

 
 

909

 
 

80128

 
 

109

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML

CVE-2009-4449

Date: (C)2009-12-29   (M)2015-12-16 


Directory traversal vulnerability in MyBB (aka MyBulletinBoard) 1.4.10, and possibly earlier versions, when changing the user avatar from the gallery, allows remote authenticated users to determine the existence of files via directory traversal sequences in the avatar and possibly the gallery parameters, related to (1) admin/modules/user/users.php and (2) usercp.php.

CVSS Score: 6.3Access Vector: NETWORK
Exploit Score: 6.8Access Complexity: MEDIUM
Impact Score: 6.9Authentication: SINGLE_INSTANCE
 Confidentiality: COMPLETE
 Integrity: NONE
 Availability: NONE





Reference:
BID-37489
SECUNIA-37906
OSVDB-61359
ADV-2009-3651
http://openwall.com/lists/oss-security/2010/10/08/7
http://openwall.com/lists/oss-security/2010/10/11/8
http://openwall.com/lists/oss-security/2010/12/06/2
http://blog.mybboard.net/2009/12/29/mybb-1-4-11-released-minor-patch-security-update/
http://dev.mybboard.net/issues/617
http://dev.mybboard.net/projects/mybb/repository/revisions/4663/diff/branches/1.4-stable/admin/modules/user/users.php
http://dev.mybboard.net/projects/mybb/repository/revisions/4663/diff/branches/1.4-stable/usercp.php

CPE    1
cpe:/a:mybboard:mybb:1.4.10
CWE    1
CWE-22

© 2013 SecPod Technologies