Directory traversal vulnerability in MyBB (aka MyBulletinBoard) 1.4.10, and possibly earlier versions, when changing the user avatar from the gallery, allows remote authenticated users to determine the existence of files via directory traversal sequences in the avatar and possibly the gallery parameters, related to (1) admin/modules/user/users.php and (2) usercp.php.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2009-12-29T20:15:00

Updated: 2011-01-04T10:00:00

Reserved: 2009-12-29T00:00:00


Link: CVE-2009-4449

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2009-12-29T20:41:20.500

Modified: 2024-01-26T17:46:37.540


Link: CVE-2009-4449

JSON object: View

cve-icon Redhat Information

No data.

CWE