CVE-2010-4628: Medium severity Mybb Mybb vulnerability
Published Dec 30, 2010
·Updated
member.php in MyBB (aka MyBulletinBoard) before 1.4.12 makes a certain superfluous call to the SQL COUNT function, which allows remote attackers to cause a denial of service (resource consumption) by making requests to member.php that trigger scans of the entire users table.
Affected Software
37 affected components
Mybb Mybb<=1.4.11
Mybb Mybb=1.00
Mybb Mybb=1.01
Mybb Mybb=1.1.0
Mybb Mybb=1.1.1
Mybb Mybb=1.1.2
Mybb Mybb=1.1.3
Mybb Mybb=1.1.4
Mybb Mybb=1.1.5
Mybb Mybb=1.1.6
Mybb Mybb=1.1.7
Mybb Mybb=1.1.8
Mybb Mybb=1.02
Mybb Mybb=1.2
Mybb Mybb=1.2.0
Mybb Mybb=1.2.1
Mybb Mybb=1.2.2
Mybb Mybb=1.2.3
Mybb Mybb=1.2.4
Mybb Mybb=1.2.5
Mybb Mybb=1.2.6
Mybb Mybb=1.2.7
Mybb Mybb=1.2.8
Mybb Mybb=1.2.9
Mybb Mybb=1.2.10
Mybb Mybb=1.2.11
Mybb Mybb=1.2.12
Mybb Mybb=1.2.13
Mybb Mybb=1.03
Mybb Mybb=1.04
Mybb Mybb=1.4.0
Mybb Mybb=1.4.2
Mybb Mybb=1.4.3
Mybb Mybb=1.4.6
Mybb Mybb=1.4.8
Mybb Mybb=1.4.9
Mybb Mybb=1.4.10
Remediation
Event History
Dec 30, 2010
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-4628?
CVE-2010-4628 has a high severity rating due to its potential to cause denial of service through excessive resource consumption.
2
How do I fix CVE-2010-4628?
To fix CVE-2010-4628, upgrade MyBB to version 1.4.12 or later.
3
What systems are affected by CVE-2010-4628?
CVE-2010-4628 affects MyBB versions prior to 1.4.12 including several versions of 1.2 and 1.4.
4
What type of vulnerability is CVE-2010-4628?
CVE-2010-4628 is a denial of service vulnerability due to an inefficient SQL query.
5
Can CVE-2010-4628 be exploited remotely?
Yes, CVE-2010-4628 can be exploited remotely by sending specially crafted requests to member.php.