CVE Vulnerabilities

CVE-2010-4626

Published: Dec 30, 2010 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.1 MEDIUM
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The my_rand function in functions.php in MyBB (aka MyBulletinBoard) before 1.4.12 does not properly use the PHP mt_rand function, which makes it easier for remote attackers to obtain access to an arbitrary account by requesting a reset of the accounts password, and then conducting a brute-force attack.

Affected Software

NameVendorStart VersionEnd Version
MybbMybb*1.4.11 (including)
MybbMybb1.00 (including)1.00 (including)
MybbMybb1.01 (including)1.01 (including)
MybbMybb1.1.0 (including)1.1.0 (including)
MybbMybb1.1.1 (including)1.1.1 (including)
MybbMybb1.1.2 (including)1.1.2 (including)
MybbMybb1.1.3 (including)1.1.3 (including)
MybbMybb1.1.4 (including)1.1.4 (including)
MybbMybb1.1.5 (including)1.1.5 (including)
MybbMybb1.1.6 (including)1.1.6 (including)
MybbMybb1.1.7 (including)1.1.7 (including)
MybbMybb1.1.8 (including)1.1.8 (including)
MybbMybb1.02 (including)1.02 (including)
MybbMybb1.2 (including)1.2 (including)
MybbMybb1.2.0 (including)1.2.0 (including)
MybbMybb1.2.1 (including)1.2.1 (including)
MybbMybb1.2.2 (including)1.2.2 (including)
MybbMybb1.2.3 (including)1.2.3 (including)
MybbMybb1.2.4 (including)1.2.4 (including)
MybbMybb1.2.5 (including)1.2.5 (including)
MybbMybb1.2.6 (including)1.2.6 (including)
MybbMybb1.2.7 (including)1.2.7 (including)
MybbMybb1.2.8 (including)1.2.8 (including)
MybbMybb1.2.9 (including)1.2.9 (including)
MybbMybb1.2.10 (including)1.2.10 (including)
MybbMybb1.2.11 (including)1.2.11 (including)
MybbMybb1.2.12 (including)1.2.12 (including)
MybbMybb1.2.13 (including)1.2.13 (including)
MybbMybb1.03 (including)1.03 (including)
MybbMybb1.04 (including)1.04 (including)
MybbMybb1.4.0 (including)1.4.0 (including)
MybbMybb1.4.2 (including)1.4.2 (including)
MybbMybb1.4.3 (including)1.4.3 (including)
MybbMybb1.4.6 (including)1.4.6 (including)
MybbMybb1.4.8 (including)1.4.8 (including)
MybbMybb1.4.9 (including)1.4.9 (including)
MybbMybb1.4.10 (including)1.4.10 (including)

References