CVE Vulnerabilities

CVE-2006-3954

Published: Aug 01, 2006 | Modified: Oct 17, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Directory traversal vulnerability in usercp.php in MyBB (aka MyBulletinBoard) 1.x allows remote attackers to read arbitrary files via a .. (dot dot) in the gallery parameter in a (1) avatar or (2) do_avatar action.

Affected Software

Name Vendor Start Version End Version
Mybulletinboard Mybulletinboard 1.0.1 (including) 1.0.1 (including)
Mybulletinboard Mybulletinboard 1.0.2 (including) 1.0.2 (including)
Mybulletinboard Mybulletinboard 1.0.3 (including) 1.0.3 (including)
Mybulletinboard Mybulletinboard 1.0.4 (including) 1.0.4 (including)
Mybulletinboard Mybulletinboard 1.0_final (including) 1.0_final (including)
Mybulletinboard Mybulletinboard 1.0_pr2 (including) 1.0_pr2 (including)
Mybulletinboard Mybulletinboard 1.0_preview_release_2 (including) 1.0_preview_release_2 (including)
Mybulletinboard Mybulletinboard 1.00_rc1 (including) 1.00_rc1 (including)
Mybulletinboard Mybulletinboard 1.00_rc2 (including) 1.00_rc2 (including)
Mybulletinboard Mybulletinboard 1.0_rc2 (including) 1.0_rc2 (including)
Mybulletinboard Mybulletinboard 1.00_rc3 (including) 1.00_rc3 (including)
Mybulletinboard Mybulletinboard 1.0_rc4 (including) 1.0_rc4 (including)
Mybulletinboard Mybulletinboard 1.00_rc4 (including) 1.00_rc4 (including)
Mybulletinboard Mybulletinboard 1.00_rc4_security_patch (including) 1.00_rc4_security_patch (including)
Mybulletinboard Mybulletinboard 1.01 (including) 1.01 (including)
Mybulletinboard Mybulletinboard 1.1 (including) 1.1 (including)
Mybulletinboard Mybulletinboard 1.1.1 (including) 1.1.1 (including)
Mybulletinboard Mybulletinboard 1.1.2 (including) 1.1.2 (including)
Mybulletinboard Mybulletinboard 1.1.3 (including) 1.1.3 (including)
Mybulletinboard Mybulletinboard 1.1.4 (including) 1.1.4 (including)
Mybulletinboard Mybulletinboard 1.1.5 (including) 1.1.5 (including)
Mybulletinboard Mybulletinboard 1.1.7 (including) 1.1.7 (including)
Mybulletinboard Mybulletinboard 1.04 (including) 1.04 (including)
Mybulletinboard Mybulletinboard 1.10 (including) 1.10 (including)
Mybulletinboard Mybulletinboard 1.14 (including) 1.14 (including)
Mybulletinboard Mybulletinboard 1.20 (including) 1.20 (including)

References