CVE-2010-4625: Infoleak
Published Dec 30, 2010
·Updated
MyBB (aka MyBulletinBoard) before 1.4.12 does not properly handle a configuration with a visible forum that contains hidden threads, which allows remote attackers to obtain sensitive information by reading the Latest Threads block of the Portal Page.
Affected Software
37 affected components
Mybb Mybb=1.2.10
Mybb Mybb=1.2.8
Mybb Mybb=1.4.3
Mybb Mybb=1.04
Mybb Mybb=1.1.1
Mybb Mybb=1.1.3
Mybb Mybb=1.2.2
Mybb Mybb=1.2.9
Mybb Mybb=1.4.8
Mybb Mybb=1.2.1
Mybb Mybb=1.01
Mybb Mybb=1.1.6
Mybb Mybb=1.2.6
Mybb Mybb=1.4.0
Mybb Mybb=1.2.0
Mybb Mybb=1.4.9
Mybb Mybb=1.02
Mybb Mybb=1.2.5
Mybb Mybb=1.4.2
Mybb Mybb=1.1.8
Mybb Mybb=1.2.11
Mybb Mybb=1.1.5
Mybb Mybb=1.2.13
Mybb Mybb=1.4.6
Mybb Mybb=1.1.0
Mybb Mybb=1.2.3
Mybb Mybb=1.4.10
Mybb Mybb=1.2.7
Mybb Mybb=1.1.7
Mybb Mybb=1.1.4
Mybb Mybb=1.03
Mybb Mybb<=1.4.11
Mybb Mybb=1.00
Mybb Mybb=1.2.4
Mybb Mybb=1.2
Mybb Mybb=1.2.12
Mybb Mybb=1.1.2
Remediation
Event History
Dec 30, 2010
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
Is there a workaround for CVE-2010-4625 if I cannot update MyBB?
A workaround is to restrict access to the Latest Threads block to trusted users, although updating is strongly recommended.