CVE-2009-4449
Directory traversal vulnerability in MyBB (aka MyBulletinBoard) 1.4.10, and possibly earlier versions, when changing the user avatar from the gallery, allows remote authenticated users to determine the existence of files via directory traversal…
Does this matter?
Lower severity and a low EPSS score (2.70%). Track it; it rarely justifies an emergency change on its own.
Description
Directory traversal vulnerability in MyBB (aka MyBulletinBoard) 1.4.10, and possibly earlier versions, when changing the user avatar from the gallery, allows remote authenticated users to determine the existence of files via directory traversal sequences in the avatar and possibly the gallery parameters, related to (1) admin/modules/user/users.php and (2) usercp.php.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 2.70% probability · 85th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- mybb/mybb
- Source
- cve@mitre.org
References
- http://blog.mybboard.net/2009/12/29/mybb-1-4-11-released-minor-patch-security-update/Release Notes
- http://dev.mybboard.net/issues/617Broken Link
- http://dev.mybboard.net/projects/mybb/repository/revisions/4663/diff/branches/1.4-stable/admin/modules/user/users.phpBroken Link, Exploit
- http://dev.mybboard.net/projects/mybb/repository/revisions/4663/diff/branches/1.4-stable/usercp.phpBroken Link, Exploit
- http://openwall.com/lists/oss-security/2010/10/08/7Mailing List
- http://openwall.com/lists/oss-security/2010/10/11/8Mailing List
- http://openwall.com/lists/oss-security/2010/12/06/2Mailing List
- http://osvdb.org/61359Broken Link
- http://secunia.com/advisories/37906Broken Link, Vendor Advisory
- http://www.securityfocus.com/bid/37489Broken Link, Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2009/3651Permissions Required, Vendor Advisory
- http://blog.mybboard.net/2009/12/29/mybb-1-4-11-released-minor-patch-security-update/Release Notes
- http://dev.mybboard.net/issues/617Broken Link
- http://dev.mybboard.net/projects/mybb/repository/revisions/4663/diff/branches/1.4-stable/admin/modules/user/users.phpBroken Link, Exploit
- http://dev.mybboard.net/projects/mybb/repository/revisions/4663/diff/branches/1.4-stable/usercp.phpBroken Link, Exploit
- http://openwall.com/lists/oss-security/2010/10/08/7Mailing List
- http://openwall.com/lists/oss-security/2010/10/11/8Mailing List
- http://openwall.com/lists/oss-security/2010/12/06/2Mailing List
- http://osvdb.org/61359Broken Link
- http://secunia.com/advisories/37906Broken Link, Vendor Advisory
- http://www.securityfocus.com/bid/37489Broken Link, Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2009/3651Permissions Required, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.