CVE-2010-4629: Medium severity Mybb Mybb vulnerability
Published Dec 30, 2010
·Updated
MyBB (aka MyBulletinBoard) before 1.4.12 does not properly restrict uid values for group join requests, which allows remote attackers to cause a denial of service (resource consumption) by using guest access to submit join request forms for moderated groups, related to usercp.php and managegroup.php.
Affected Software
37 affected components
Mybb Mybb=1.2.10
Mybb Mybb=1.2.8
Mybb Mybb=1.4.3
Mybb Mybb=1.04
Mybb Mybb=1.1.1
Mybb Mybb=1.1.3
Mybb Mybb=1.2.2
Mybb Mybb=1.2.9
Mybb Mybb=1.4.8
Mybb Mybb=1.2.1
Mybb Mybb=1.01
Mybb Mybb=1.1.6
Mybb Mybb=1.2.6
Mybb Mybb=1.4.0
Mybb Mybb=1.2.0
Mybb Mybb=1.4.9
Mybb Mybb=1.02
Mybb Mybb=1.2.5
Mybb Mybb=1.4.2
Mybb Mybb=1.1.8
Mybb Mybb=1.2.11
Mybb Mybb=1.1.5
Mybb Mybb=1.2.13
Mybb Mybb=1.4.6
Mybb Mybb=1.1.0
Mybb Mybb=1.2.3
Mybb Mybb=1.4.10
Mybb Mybb=1.2.7
Mybb Mybb=1.1.7
Mybb Mybb=1.1.4
Mybb Mybb=1.03
Mybb Mybb<=1.4.11
Mybb Mybb=1.00
Mybb Mybb=1.2.4
Mybb Mybb=1.2
Mybb Mybb=1.2.12
Mybb Mybb=1.1.2
Remediation
Event History
Dec 30, 2010
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-4629?
CVE-2010-4629 is classified as a denial of service vulnerability that can lead to resource exhaustion.
2
How do I fix CVE-2010-4629?
To address CVE-2010-4629, upgrade MyBB to version 1.4.12 or later.
3
Which versions of MyBB are affected by CVE-2010-4629?
MyBB versions before 1.4.12 are affected by CVE-2010-4629.
4
What type of attacks can exploit CVE-2010-4629?
Attackers can exploit CVE-2010-4629 by submitting group join requests using guest access, leading to service denial.
5
Is CVE-2010-4629 a local or remote vulnerability?
CVE-2010-4629 is a remote vulnerability that allows attackers to exploit it without local access.