CVE-2009-4448
Summary
| CVE | CVE-2009-4448 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-12-29 20:41:20 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | inc/functions_time.php in MyBB (aka MyBulletinBoard) 1.4.10, and possibly earlier versions, allows remote attackers to cause a denial of service (CPU consumption) via a crafted request with a large year value, which triggers a long loop, as reachable through member.php and possibly other vectors. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
PartialAV:N/AC:L/Au:N/C:N/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| MyBB Blog » Blog Archive » MyBB 1.4.11 Released – Minor Patch & Security Update | af854a3a-2127-422b-91ae-364da2661108 | blog.mybboard.net | Patch |
| MyBB - Bug #600: Intensive loop in functions_time.php - MyBulletinBoard Development Site | af854a3a-2127-422b-91ae-364da2661108 | dev.mybboard.net | Patch |
| oss-security - Re: CVE request: mybb before 1.4.11 and before 1.4.12 | af854a3a-2127-422b-91ae-364da2661108 | openwall.com | |
| MyBB Avatar Change File Enumeration Security Issue - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| oss-security - Re: CVE request: mybb before 1.4.11 and before 1.4.12 | af854a3a-2127-422b-91ae-364da2661108 | openwall.com | |
| dev.mybboard.net/projects/mybb/repository/revisions/4613/diff/branches/1.4-sta... | af854a3a-2127-422b-91ae-364da2661108 | dev.mybboard.net | |
| oss-security - CVE request: mybb before 1.4.11 and before 1.4.12 | af854a3a-2127-422b-91ae-364da2661108 | openwall.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.