Lucene search

K
cvelistMitreCVELIST:CVE-2009-4449
HistoryDec 29, 2009 - 8:15 p.m.

CVE-2009-4449

2009-12-2920:15:00
mitre
www.cve.org
1

AI Score

6.2

Confidence

High

EPSS

0.004

Percentile

73.4%

Directory traversal vulnerability in MyBB (aka MyBulletinBoard) 1.4.10, and possibly earlier versions, when changing the user avatar from the gallery, allows remote authenticated users to determine the existence of files via directory traversal sequences in the avatar and possibly the gallery parameters, related to (1) admin/modules/user/users.php and (2) usercp.php.

AI Score

6.2

Confidence

High

EPSS

0.004

Percentile

73.4%

Related for CVELIST:CVE-2009-4449