NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 15871 | CVE-2010-4624 | MyBB (aka MyBulletinBoard) before 1.4.12 allows remote authenticated users to bypass intended restrictions on the number of [img] MyCodes by editing a post after it has been created. | 2 | 3.5 | Low | 2017-01-18 | 2011-01-11 | View | |
| 15872 | CVE-2010-4625 | MyBB (aka MyBulletinBoard) before 1.4.12 does not properly handle a configuration with a visible forum that contains hidden threads, which allows remote attackers to obtain sensitive information by reading the Latest Threads block of the Portal Page. | 2 | 5 | Medium | 2017-01-18 | 2011-01-11 | View | |
| 15873 | CVE-2010-4626 | The my_rand function in functions.php in MyBB (aka MyBulletinBoard) before 1.4.12 does not properly use the PHP mt_rand function, which makes it easier for remote attackers to obtain access to an arbitrary account by requesting a reset of the account"s password, and then conducting a brute-force attack. | 2 | 5.1 | Medium | 2017-01-18 | 2011-01-11 | View | |
| 15874 | CVE-2010-4627 | Cross-site request forgery (CSRF) vulnerability in usercp2.php in MyBB (aka MyBulletinBoard) before 1.4.12 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. | 2 | 6.8 | Medium | 2017-01-18 | 2011-01-11 | View | |
| 15875 | CVE-2010-4628 | member.php in MyBB (aka MyBulletinBoard) before 1.4.12 makes a certain superfluous call to the SQL COUNT function, which allows remote attackers to cause a denial of service (resource consumption) by making requests to member.php that trigger scans of the entire users table. | 2 | 5 | Medium | 2017-01-18 | 2011-01-11 | View |
Page 3175 of 17672, showing 5 records out of 88360 total, starting on record 15871, ending on 15875