5.1
CVSSv2

CVE-2010-4626

Published: 30/12/2010 Updated: 17/08/2017
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
VMScore: 454
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

The my_rand function in functions.php in MyBB (aka MyBulletinBoard) prior to 1.4.12 does not properly use the PHP mt_rand function, which makes it easier for remote malicious users to obtain access to an arbitrary account by requesting a reset of the account's password, and then conducting a brute-force attack.

Vulnerable Product Search on Vulmon Subscribe to Product

mybb mybb 1.4.10

mybb mybb 1.4.9

mybb mybb 1.2.12

mybb mybb 1.2.10

mybb mybb 1.2.1

mybb mybb 1.2.2

mybb mybb 1.1.4

mybb mybb 1.1.5

mybb mybb 1.01

mybb mybb 1.04

mybb mybb 1.03

mybb mybb 1.4.8

mybb mybb 1.4.6

mybb mybb 1.2.0

mybb mybb 1.2

mybb mybb 1.2.9

mybb mybb 1.2.3

mybb mybb 1.2.4

mybb mybb 1.1.2

mybb mybb 1.1.0

mybb mybb 1.4.3

mybb mybb 1.4.2

mybb mybb 1.2.8

mybb mybb 1.2.6

mybb mybb 1.2.5

mybb mybb 1.1.7

mybb mybb 1.1.3

mybb mybb 1.1.1

mybb mybb

mybb mybb 1.4.0

mybb mybb 1.2.11

mybb mybb 1.2.7

mybb mybb 1.2.13

mybb mybb 1.1.6

mybb mybb 1.1.8

mybb mybb 1.00

mybb mybb 1.02