CVE-2008-4929

MyBB (aka MyBulletinBoard) 1.4.2 uses insufficient randomness to compose filenames of uploaded files used as attachments, which makes it easier for remote attackers to read these files by guessing filenames.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mybb:mybb:1.4.2:*:*:*:*:*:*:*

History

17 Jan 2025, 16:15

Type Values Removed Values Added
References (BID) http://www.securityfocus.com/bid/31936 - Broken Link, Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/31936 - Broken Link, Third Party Advisory, VDB Entry
References (MLIST) http://www.openwall.com/lists/oss-security/2008/11/01/2 - Exploit, Mailing List () http://www.openwall.com/lists/oss-security/2008/11/01/2 - Exploit, Mailing List
References (VUPEN) http://www.vupen.com/english/advisories/2008/2967 - Broken Link () http://www.vupen.com/english/advisories/2008/2967 - Broken Link
References (FULLDISC) http://archives.neohapsis.com/archives/fulldisclosure/2008-10/0472.html - Broken Link, Exploit () http://archives.neohapsis.com/archives/fulldisclosure/2008-10/0472.html - Broken Link, Exploit
References (BUGTRAQ) http://archives.neohapsis.com/archives/bugtraq/2008-10/0203.html - Broken Link, Exploit () http://archives.neohapsis.com/archives/bugtraq/2008-10/0203.html - Broken Link, Exploit

14 Feb 2024, 16:09

Type Values Removed Values Added
CWE CWE-310 CWE-330
CVSS v2 : 5.0
v3 : unknown
v2 : 5.0
v3 : 7.5
References (BUGTRAQ) http://archives.neohapsis.com/archives/bugtraq/2008-10/0203.html - Exploit (BUGTRAQ) http://archives.neohapsis.com/archives/bugtraq/2008-10/0203.html - Broken Link, Exploit
References (VUPEN) http://www.vupen.com/english/advisories/2008/2967 - (VUPEN) http://www.vupen.com/english/advisories/2008/2967 - Broken Link
References (MLIST) http://www.openwall.com/lists/oss-security/2008/11/01/2 - Exploit (MLIST) http://www.openwall.com/lists/oss-security/2008/11/01/2 - Exploit, Mailing List
References (BID) http://www.securityfocus.com/bid/31936 - (BID) http://www.securityfocus.com/bid/31936 - Broken Link, Third Party Advisory, VDB Entry
References (FULLDISC) http://archives.neohapsis.com/archives/fulldisclosure/2008-10/0472.html - Exploit (FULLDISC) http://archives.neohapsis.com/archives/fulldisclosure/2008-10/0472.html - Broken Link, Exploit

Information

Published : 2008-11-04 21:00

Updated : 2025-01-17 16:15


NVD link : CVE-2008-4929

Mitre link : CVE-2008-4929


JSON object : View

Products Affected

mybb

  • mybb
CWE
CWE-330

Use of Insufficiently Random Values