CVE-2008-4929

MyBB (aka MyBulletinBoard) 1.4.2 uses insufficient randomness to compose filenames of uploaded files used as attachments, which makes it easier for remote attackers to read these files by guessing filenames.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mybb:mybb:1.4.2:*:*:*:*:*:*:*

History

21 Nov 2024, 00:52

Type Values Removed Values Added
References () http://archives.neohapsis.com/archives/bugtraq/2008-10/0203.html - Broken Link, Exploit () http://archives.neohapsis.com/archives/bugtraq/2008-10/0203.html - Broken Link, Exploit
References () http://archives.neohapsis.com/archives/fulldisclosure/2008-10/0472.html - Broken Link, Exploit () http://archives.neohapsis.com/archives/fulldisclosure/2008-10/0472.html - Broken Link, Exploit
References () http://www.openwall.com/lists/oss-security/2008/11/01/2 - Exploit, Mailing List () http://www.openwall.com/lists/oss-security/2008/11/01/2 - Exploit, Mailing List
References () http://www.securityfocus.com/bid/31936 - Broken Link, Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/31936 - Broken Link, Third Party Advisory, VDB Entry
References () http://www.vupen.com/english/advisories/2008/2967 - Broken Link () http://www.vupen.com/english/advisories/2008/2967 - Broken Link

14 Feb 2024, 16:09

Type Values Removed Values Added
CWE CWE-310 CWE-330
References (BUGTRAQ) http://archives.neohapsis.com/archives/bugtraq/2008-10/0203.html - Exploit (BUGTRAQ) http://archives.neohapsis.com/archives/bugtraq/2008-10/0203.html - Broken Link, Exploit
References (VUPEN) http://www.vupen.com/english/advisories/2008/2967 - (VUPEN) http://www.vupen.com/english/advisories/2008/2967 - Broken Link
References (BID) http://www.securityfocus.com/bid/31936 - (BID) http://www.securityfocus.com/bid/31936 - Broken Link, Third Party Advisory, VDB Entry
References (FULLDISC) http://archives.neohapsis.com/archives/fulldisclosure/2008-10/0472.html - Exploit (FULLDISC) http://archives.neohapsis.com/archives/fulldisclosure/2008-10/0472.html - Broken Link, Exploit
References (MLIST) http://www.openwall.com/lists/oss-security/2008/11/01/2 - Exploit (MLIST) http://www.openwall.com/lists/oss-security/2008/11/01/2 - Exploit, Mailing List
CVSS v2 : 5.0
v3 : unknown
v2 : 5.0
v3 : 7.5

Information

Published : 2008-11-04 21:00

Updated : 2024-11-21 00:52


NVD link : CVE-2008-4929

Mitre link : CVE-2008-4929

CVE.ORG link : CVE-2008-4929


JSON object : View

Products Affected

mybb

  • mybb
CWE
CWE-330

Use of Insufficiently Random Values