CVE-2009-4449

Published Dec 29, 2009

Last updated 10 months ago

Overview

Description
Directory traversal vulnerability in MyBB (aka MyBulletinBoard) 1.4.10, and possibly earlier versions, when changing the user avatar from the gallery, allows remote authenticated users to determine the existence of files via directory traversal sequences in the avatar and possibly the gallery parameters, related to (1) admin/modules/user/users.php and (2) usercp.php.
Source
cve@mitre.org
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
6.5
Impact score
3.6
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Severity
MEDIUM

CVSS 2.0

Type
Primary
Base score
6.3
Impact score
6.9
Exploitability score
6.8
Vector string
AV:N/AC:M/Au:S/C:C/I:N/A:N

Weaknesses

nvd@nist.gov
CWE-22

Social media

Hype score
Not currently trending

Configurations