CVE-2009-4449
Summary
| CVE | CVE-2009-4449 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-12-29 20:41:20 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Directory traversal vulnerability in MyBB (aka MyBulletinBoard) 1.4.10, and possibly earlier versions, when changing the user avatar from the gallery, allows remote authenticated users to determine the existence of files via directory traversal sequences in the avatar and possibly the gallery parameters, related to (1) admin/modules/user/users.php and (2) usercp.php. |
Risk And Classification
Primary CVSS: v3.1 6.5 MEDIUM from [email protected]
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Problem Types: CWE-22 | n/a
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 6.5 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
| 2.0 | [email protected] | Primary | 6.3 | AV:N/AC:M/Au:S/C:C/I:N/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
NoneAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
SingleConfidentiality
CompleteIntegrity
NoneAvailability
NoneAV:N/AC:M/Au:S/C:C/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| MyBB Blog » Blog Archive » MyBB 1.4.11 Released – Minor Patch & Security Update | af854a3a-2127-422b-91ae-364da2661108 | blog.mybboard.net | Release Notes |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Permissions Required, Vendor Advisory |
| dev.mybboard.net/projects/mybb/repository/revisions/4663/diff/branches/1.4-sta... | af854a3a-2127-422b-91ae-364da2661108 | dev.mybboard.net | Broken Link, Exploit |
| oss-security - Re: CVE request: mybb before 1.4.11 and before 1.4.12 | af854a3a-2127-422b-91ae-364da2661108 | openwall.com | Mailing List |
| MyBB Avatar Change File Enumeration Security Issue - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link, Vendor Advisory |
| MyBB 'Avatar' Parameter File Enumeration Information Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Broken Link, Third Party Advisory, VDB Entry |
| oss-security - Re: CVE request: mybb before 1.4.11 and before 1.4.12 | af854a3a-2127-422b-91ae-364da2661108 | openwall.com | Mailing List |
| dev.mybboard.net/projects/mybb/repository/revisions/4663/diff/branches/1.4-sta... | af854a3a-2127-422b-91ae-364da2661108 | dev.mybboard.net | Broken Link, Exploit |
| osvdb.org/61359 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | Broken Link |
| MyBB - Bug #617: Avatar gallery url sanitation - MyBulletinBoard Development Site | af854a3a-2127-422b-91ae-364da2661108 | dev.mybboard.net | Broken Link |
| oss-security - CVE request: mybb before 1.4.11 and before 1.4.12 | af854a3a-2127-422b-91ae-364da2661108 | openwall.com | Mailing List |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.