CVE-2009-4448: Medium severity mybb vulnerability
inc/functionstime.php in MyBB (aka MyBulletinBoard) 1.4.10, and possibly earlier versions, allows remote attackers to cause a denial of service (CPU consumption) via a crafted request with a large year value, which triggers a long loop, as reachable through member.php and possibly other vectors.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-4448?
CVE-2009-4448 has a severity level of medium due to the potential for denial of service.
How do I fix CVE-2009-4448?
To fix CVE-2009-4448, upgrade MyBB to version 1.4.11 or later, which includes the minor patch addressing this vulnerability.
What systems are affected by CVE-2009-4448?
CVE-2009-4448 affects MyBB version 1.4.10 and possibly earlier versions.
What type of attack does CVE-2009-4448 facilitate?
CVE-2009-4448 can facilitate a denial of service attack by causing excessive CPU consumption through crafted requests.
What components of MyBB does CVE-2009-4448 impact?
CVE-2009-4448 impacts the functions_time.php file in MyBB, specifically when handling large year values.