MyBB (aka MyBulletinBoard) 1.4.2 uses insufficient randomness to compose filenames of uploaded files used as attachments, which makes it easier for remote attackers to read these files by guessing filenames.
The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/31936 | vdb entry third party advisory broken link |
http://archives.neohapsis.com/archives/bugtraq/2008-10/0203.html | mailing list exploit broken link |
http://www.vupen.com/english/advisories/2008/2967 | vdb entry broken link |
http://archives.neohapsis.com/archives/fulldisclosure/2008-10/0472.html | mailing list exploit broken link |
http://www.openwall.com/lists/oss-security/2008/11/01/2 | mailing list exploit |