Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2009-4449

Опубликовано: 29 дек. 2009
Источник: nvd
CVSS3: 6.5
CVSS2: 6.3
EPSS Низкий

Описание

Directory traversal vulnerability in MyBB (aka MyBulletinBoard) 1.4.10, and possibly earlier versions, when changing the user avatar from the gallery, allows remote authenticated users to determine the existence of files via directory traversal sequences in the avatar and possibly the gallery parameters, related to (1) admin/modules/user/users.php and (2) usercp.php.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:mybb:mybb:1.4.10:*:*:*:*:*:*:*

EPSS

Процентиль: 65%
0.00501
Низкий

6.5 Medium

CVSS3

6.3 Medium

CVSS2

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 6.5
github
почти 4 года назад

Directory traversal vulnerability in MyBB (aka MyBulletinBoard) 1.4.10, and possibly earlier versions, when changing the user avatar from the gallery, allows remote authenticated users to determine the existence of files via directory traversal sequences in the avatar and possibly the gallery parameters, related to (1) admin/modules/user/users.php and (2) usercp.php.

EPSS

Процентиль: 65%
0.00501
Низкий

6.5 Medium

CVSS3

6.3 Medium

CVSS2

Дефекты

CWE-22