CVE-2008-4929

HIGH

MyBB 1.4.2 - Insufficiently Random Filename Generation for Uploaded Attachments

Title source: llm
STIX 2.1

Description

MyBB (aka MyBulletinBoard) 1.4.2 uses insufficient randomness to compose filenames of uploaded files used as attachments, which makes it easier for remote attackers to read these files by guessing filenames.

References (5)

Core 5
Core References
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/31936
Broken Link, Exploit mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2008-10/0203.html
Broken Link vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/2967
Broken Link, Exploit mailing-list x_refsource_fulldisc
http://archives.neohapsis.com/archives/fulldisclosure/2008-10/0472.html
Exploit, Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2008/11/01/2

Scores

CVSS v3 7.5
EPSS 0.0224
EPSS Percentile 80.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-330
Status published
Products (1)
mybb/mybb 1.4.2
Published Nov 04, 2008
Tracked Since Feb 18, 2026