5
CVSSv2

CVE-2010-4628

Published: 30/12/2010 Updated: 17/08/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

member.php in MyBB (aka MyBulletinBoard) prior to 1.4.12 makes a certain superfluous call to the SQL COUNT function, which allows remote malicious users to cause a denial of service (resource consumption) by making requests to member.php that trigger scans of the entire users table.

Affected Products

Vendor Product Versions
MybbMybb1.00, 1.01, 1.1.0, 1.1.1, 1.1.2, 1.1.3, 1.1.4, 1.1.5, 1.1.6, 1.1.7, 1.1.8, 1.02, 1.2, 1.2.0, 1.2.1, 1.2.2, 1.2.3, 1.2.4, 1.2.5, 1.2.6, 1.2.7, 1.2.8, 1.2.9, 1.2.10, 1.2.11, 1.2.12, 1.2.13, 1.03, 1.04, 1.4.0, 1.4.2, 1.4.3, 1.4.6, 1.4.8, 1.4.9, 1.4.10, 1.4.11