5

CVE-2006-3954

Exploit

Directory traversal vulnerability in usercp.php in MyBB (aka MyBulletinBoard) 1.x allows remote attackers to read arbitrary files via a .. (dot dot) in the gallery parameter in a (1) avatar or (2) do_avatar action.

Data is provided by the National Vulnerability Database (NVD)
MybulletinboardMybulletinboard Version1.0.1
MybulletinboardMybulletinboard Version1.0.2
MybulletinboardMybulletinboard Version1.0.3
MybulletinboardMybulletinboard Version1.0.4
MybulletinboardMybulletinboard Version1.0_final
MybulletinboardMybulletinboard Version1.0_pr2
MybulletinboardMybulletinboard Version1.0_preview_release_2
MybulletinboardMybulletinboard Version1.00_rc1
MybulletinboardMybulletinboard Version1.00_rc2
MybulletinboardMybulletinboard Version1.0_rc2
MybulletinboardMybulletinboard Version1.00_rc3
MybulletinboardMybulletinboard Version1.0_rc4
MybulletinboardMybulletinboard Version1.00_rc4
MybulletinboardMybulletinboard Version1.00_rc4_security_patch
MybulletinboardMybulletinboard Version1.1.1
MybulletinboardMybulletinboard Version1.1.2
MybulletinboardMybulletinboard Version1.1.3
MybulletinboardMybulletinboard Version1.1.4
MybulletinboardMybulletinboard Version1.1.5
MybulletinboardMybulletinboard Version1.1.7
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.27% 0.502
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N