Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2010-4629

EPSS 1.19% · P79
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2010-4629

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
MyBB (aka MyBulletinBoard) before 1.4.12 does not properly restrict uid values for group join requests, which allows remote attackers to cause a denial of service (resource consumption) by using guest access to submit join request forms for moderated groups, related to usercp.php and managegroup.php.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
MyBB拒绝服务漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
MyBB(又名MyBulletinBoard)是MyBB团队开发的一套用PHP和MySQL开发的免费且基于Web的论坛软件。该软件具有简单易用、支持多国语言、可扩展等特点。 MyBB(又名MyBulletinBoard)1.4.12之前版本对加入请求组的uid值没有经过正确的限制。远程攻击者可以通过使用客户访问来为moderated组提交加入请求表单,从而导致拒绝服务(资源消耗)。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2010-4629

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2010-4629

Please Login to view more intelligence information

Same Patch Batch · n/a · 2010-12-30 · 38 CVEs total

CVE-2010-4161Red Hat Enterprise Linux net/ipv4/udp.c文件资源管理错误漏洞
CVE-2010-4638JQuarks函数SQL注入漏洞
CVE-2010-4639Intendance MySource Matrix index.php文件SQL注入漏洞
CVE-2010-4640XWiki Watch 多个跨站脚本攻击漏洞
CVE-2010-4641XWiki Enterprise SQL注入漏洞
CVE-2010-4642XWiki跨站脚本攻击漏洞
CVE-2010-3848Linux kernel econet_sendmsg函数栈缓冲区错误漏洞
CVE-2010-3849Linux kernel econet_sendmsg函数资源管理错误漏洞
CVE-2010-3850Linux kernel ec_dev_ioctl函数权限许可和访问控制问题漏洞
CVE-2010-4158Linux kernel sk_run_filter函数信息泄露漏洞
CVE-2010-4637Finalcut feedlist/handler_image.php文件跨站脚本攻击漏洞
CVE-2010-4258Linux kernel kernel/exit.c文件权限许可和访问控制问题漏洞
CVE-2010-4276LiveZilla "livezilla"跨站脚本攻击漏洞
CVE-2010-4321Novell iPrint Client ienipp.ocx ActiveX控件栈缓冲区溢出漏洞
CVE-2010-4342Linux kernel aun_incoming函数资源管理错误漏洞
CVE-2010-4352D-BUS 资源管理错误漏洞
CVE-2010-4507Clear iSpot和ClearSpot多个跨站请求伪造漏洞
CVE-2010-4622IBM Tivoli Access Manager路径遍历漏洞
CVE-2010-4623IBM Tivoli Access Manager WebSEAL资源管理错误漏洞
CVE-2010-4627MyBB usercp2.php文件跨站请求伪造漏洞

Showing top 20 of 38 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2010-4629

No comments yet


Leave a comment