CVE-2008-4929
HIGHMyBB 1.4.2 - Insufficiently Random Filename Generation for Uploaded Attachments
Title source: llmDescription
MyBB (aka MyBulletinBoard) 1.4.2 uses insufficient randomness to compose filenames of uploaded files used as attachments, which makes it easier for remote attackers to read these files by guessing filenames.
References (5)
Core 5
Core References
Broken Link, Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/31936
Broken Link, Exploit mailing-list
x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2008-10/0203.html
Broken Link vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2008/2967
Broken Link, Exploit mailing-list
x_refsource_fulldisc
http://archives.neohapsis.com/archives/fulldisclosure/2008-10/0472.html
Exploit, Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2008/11/01/2
Scores
CVSS v3
7.5
EPSS
0.0224
EPSS Percentile
80.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-330
Status
published
Products (1)
mybb/mybb
1.4.2
Published
Nov 04, 2008
Tracked Since
Feb 18, 2026