CVE Vulnerabilities

CVE-2006-3954

Published: Aug 01, 2006 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Directory traversal vulnerability in usercp.php in MyBB (aka MyBulletinBoard) 1.x allows remote attackers to read arbitrary files via a .. (dot dot) in the gallery parameter in a (1) avatar or (2) do_avatar action.

Affected Software

NameVendorStart VersionEnd Version
MybulletinboardMybulletinboard1.0.1 (including)1.0.1 (including)
MybulletinboardMybulletinboard1.0.2 (including)1.0.2 (including)
MybulletinboardMybulletinboard1.0.3 (including)1.0.3 (including)
MybulletinboardMybulletinboard1.0.4 (including)1.0.4 (including)
MybulletinboardMybulletinboard1.0_final (including)1.0_final (including)
MybulletinboardMybulletinboard1.0_pr2 (including)1.0_pr2 (including)
MybulletinboardMybulletinboard1.0_preview_release_2 (including)1.0_preview_release_2 (including)
MybulletinboardMybulletinboard1.00_rc1 (including)1.00_rc1 (including)
MybulletinboardMybulletinboard1.00_rc2 (including)1.00_rc2 (including)
MybulletinboardMybulletinboard1.0_rc2 (including)1.0_rc2 (including)
MybulletinboardMybulletinboard1.00_rc3 (including)1.00_rc3 (including)
MybulletinboardMybulletinboard1.0_rc4 (including)1.0_rc4 (including)
MybulletinboardMybulletinboard1.00_rc4 (including)1.00_rc4 (including)
MybulletinboardMybulletinboard1.00_rc4_security_patch (including)1.00_rc4_security_patch (including)
MybulletinboardMybulletinboard1.01 (including)1.01 (including)
MybulletinboardMybulletinboard1.1 (including)1.1 (including)
MybulletinboardMybulletinboard1.1.1 (including)1.1.1 (including)
MybulletinboardMybulletinboard1.1.2 (including)1.1.2 (including)
MybulletinboardMybulletinboard1.1.3 (including)1.1.3 (including)
MybulletinboardMybulletinboard1.1.4 (including)1.1.4 (including)
MybulletinboardMybulletinboard1.1.5 (including)1.1.5 (including)
MybulletinboardMybulletinboard1.1.7 (including)1.1.7 (including)
MybulletinboardMybulletinboard1.04 (including)1.04 (including)
MybulletinboardMybulletinboard1.10 (including)1.10 (including)
MybulletinboardMybulletinboard1.14 (including)1.14 (including)
MybulletinboardMybulletinboard1.20 (including)1.20 (including)

References