CVE-2008-4929

MyBB (aka MyBulletinBoard) 1.4.2 uses insufficient randomness to compose filenames of uploaded files used as attachments, which makes it easier for remote attackers to read these files by guessing filenames.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mybb:mybb:1.4.2:*:*:*:*:*:*:*

History

14 Feb 2024, 16:09

Type Values Removed Values Added
CVSS v2 : 5.0
v3 : unknown
v2 : 5.0
v3 : 7.5
CWE CWE-310 CWE-330
References () http://archives.neohapsis.com/archives/bugtraq/2008-10/0203.html - Exploit () http://archives.neohapsis.com/archives/bugtraq/2008-10/0203.html - Broken Link, Exploit
References () http://archives.neohapsis.com/archives/fulldisclosure/2008-10/0472.html - Exploit () http://archives.neohapsis.com/archives/fulldisclosure/2008-10/0472.html - Broken Link, Exploit
References () http://www.openwall.com/lists/oss-security/2008/11/01/2 - Exploit () http://www.openwall.com/lists/oss-security/2008/11/01/2 - Exploit, Mailing List
References () http://www.securityfocus.com/bid/31936 - () http://www.securityfocus.com/bid/31936 - Broken Link, Third Party Advisory, VDB Entry
References () http://www.vupen.com/english/advisories/2008/2967 - () http://www.vupen.com/english/advisories/2008/2967 - Broken Link

Information

Published : 2008-11-04 21:00

Updated : 2024-02-14 16:09


NVD link : CVE-2008-4929

Mitre link : CVE-2008-4929

CVE.ORG link : CVE-2008-4929


JSON object : View

Products Affected

mybb

  • mybb
CWE
CWE-330

Use of Insufficiently Random Values