CVE Vulnerabilities

CVE-2010-3713

Published: Oct 28, 2010 | Modified: Oct 28, 2010
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

rss.php in UseBB before 1.0.11 does not properly handle forum configurations in which a user has the view permission but not the read permission, which allows remote attackers to bypass intended access restrictions by reading a forum feed in combination with a topic feed.

Affected Software

Name Vendor Start Version End Version
Usebb Usebb * 1.0.10 (including)
Usebb Usebb 0.1 (including) 0.1 (including)
Usebb Usebb 0.1.1 (including) 0.1.1 (including)
Usebb Usebb 0.2 (including) 0.2 (including)
Usebb Usebb 0.2.1 (including) 0.2.1 (including)
Usebb Usebb 0.2.2 (including) 0.2.2 (including)
Usebb Usebb 0.2.3 (including) 0.2.3 (including)
Usebb Usebb 0.2.3-a (including) 0.2.3-a (including)
Usebb Usebb 0.3 (including) 0.3 (including)
Usebb Usebb 0.3.1 (including) 0.3.1 (including)
Usebb Usebb 0.3.2 (including) 0.3.2 (including)
Usebb Usebb 0.4 (including) 0.4 (including)
Usebb Usebb 0.4.1 (including) 0.4.1 (including)
Usebb Usebb 0.5 (including) 0.5 (including)
Usebb Usebb 0.5.1 (including) 0.5.1 (including)
Usebb Usebb 0.5.1-a (including) 0.5.1-a (including)
Usebb Usebb 0.6 (including) 0.6 (including)
Usebb Usebb 0.6-a (including) 0.6-a (including)
Usebb Usebb 0.7-beta1 (including) 0.7-beta1 (including)
Usebb Usebb 0.7-beta2 (including) 0.7-beta2 (including)
Usebb Usebb 1.0 (including) 1.0 (including)
Usebb Usebb 1.0-rc1 (including) 1.0-rc1 (including)
Usebb Usebb 1.0-rc2 (including) 1.0-rc2 (including)
Usebb Usebb 1.0-rc3 (including) 1.0-rc3 (including)
Usebb Usebb 1.0.1 (including) 1.0.1 (including)
Usebb Usebb 1.0.2 (including) 1.0.2 (including)
Usebb Usebb 1.0.3 (including) 1.0.3 (including)
Usebb Usebb 1.0.4 (including) 1.0.4 (including)
Usebb Usebb 1.0.5 (including) 1.0.5 (including)
Usebb Usebb 1.0.6 (including) 1.0.6 (including)
Usebb Usebb 1.0.7 (including) 1.0.7 (including)
Usebb Usebb 1.0.9 (including) 1.0.9 (including)

References