CVE-2009-4449: Path Traversal
Published Dec 29, 2009
·Updated
Directory traversal vulnerability in MyBB (aka MyBulletinBoard) 1.4.10, and possibly earlier versions, when changing the user avatar from the gallery, allows remote authenticated users to determine the existence of files via directory traversal sequences in the avatar and possibly the gallery parameters, related to (1) admin/modules/user/users.php and (2) usercp.php.
Affected Software
2 affected components
Mybboard Mybb=1.4.10
MyBB MyBB=1.4.10
Remediation
Event History
Dec 29, 2009
CVE Published
via MITRE·08:15 PM
Data Sourced
via MITRE·08:15 PM
Description
Data Sourced
via NVD·08:41 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-4449?
CVE-2009-4449 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2009-4449?
To fix CVE-2009-4449, upgrading to MyBB version 1.4.11 or later is recommended.
3
What systems are affected by CVE-2009-4449?
CVE-2009-4449 affects MyBB versions 1.4.10 and possibly earlier versions.
4
What type of vulnerability is CVE-2009-4449?
CVE-2009-4449 is a directory traversal vulnerability.
5
Can CVE-2009-4449 be exploited by unauthenticated users?
CVE-2009-4449 requires remote authenticated users to exploit the vulnerability.