Description
inc/functions_time.php in MyBB (aka MyBulletinBoard) 1.4.10, and possibly earlier versions, allows remote attackers to cause a denial of service (CPU consumption) via a crafted request with a large year value, which triggers a long loop, as reachable through member.php and possibly other vectors.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2009-4415 | inc/functions_time.php in MyBB (aka MyBulletinBoard) 1.4.10, and possibly earlier versions, allows remote attackers to cause a denial of service (CPU consumption) via a crafted request with a large year value, which triggers a long loop, as reachable through member.php and possibly other vectors. |
References
History
Fri, 26 Sep 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mybb
Mybb mybb |
|
| CPEs | cpe:2.3:a:mybb:mybb:1.4.10:*:*:*:*:*:*:* | |
| Vendors & Products |
Mybboard
Mybboard mybb |
Mybb
Mybb mybb |
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T07:01:20.701Z
Reserved: 2009-12-29T00:00:00.000Z
Link: CVE-2009-4448
No data.
Status : Modified
Published: 2009-12-29T20:41:20.453
Modified: 2026-04-23T00:35:47.467
Link: CVE-2009-4448
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD