NVD

Id
51572  
Name
CVE-2009-4449  
Description
Directory traversal vulnerability in MyBB (aka MyBulletinBoard) 1.4.10, and possibly earlier versions, when changing the user avatar from the gallery, allows remote authenticated users to determine the existence of files via directory traversal sequences in the avatar and possibly the gallery parameters, related to (1) admin/modules/user/users.php and (2) usercp.php.  
Reject
 
CVSS Version
2  
CVSS Score
6.3  
Severity
Medium  
CVSS Base Score
6.3  
CVSS Impact Subscore
6.9  
CVSS Exploit Subscore
6.8  
CVSS Vector
(AV:N/AC:M/Au:S/C:C/I:N/A:N)  
Pub Date
2017-01-07  
Published
2009-12-29  
Modified Date
2011-01-04  
Seq
2009-4449  

Actions