Vulnerability Details CVE-2006-3954
Directory traversal vulnerability in usercp.php in MyBB (aka MyBulletinBoard) 1.x allows remote attackers to read arbitrary files via a .. (dot dot) in the gallery parameter in a (1) avatar or (2) do_avatar action.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 44.7%
CVSS Severity
CVSS v2 Score 5.0
Products affected by CVE-2006-3954
-
cpe:2.3:a:mybulletinboard:mybulletinboard:1.0.1
-
cpe:2.3:a:mybulletinboard:mybulletinboard:1.0.2
-
cpe:2.3:a:mybulletinboard:mybulletinboard:1.0.3
-
cpe:2.3:a:mybulletinboard:mybulletinboard:1.0.4
-
cpe:2.3:a:mybulletinboard:mybulletinboard:1.00_rc1
-
cpe:2.3:a:mybulletinboard:mybulletinboard:1.00_rc2
-
cpe:2.3:a:mybulletinboard:mybulletinboard:1.00_rc3
-
cpe:2.3:a:mybulletinboard:mybulletinboard:1.00_rc4
-
cpe:2.3:a:mybulletinboard:mybulletinboard:1.00_rc4_security_patch
-
cpe:2.3:a:mybulletinboard:mybulletinboard:1.01
-
cpe:2.3:a:mybulletinboard:mybulletinboard:1.04
-
cpe:2.3:a:mybulletinboard:mybulletinboard:1.0_final
-
cpe:2.3:a:mybulletinboard:mybulletinboard:1.0_pr2
-
cpe:2.3:a:mybulletinboard:mybulletinboard:1.0_preview_release_2
-
cpe:2.3:a:mybulletinboard:mybulletinboard:1.0_rc2
-
cpe:2.3:a:mybulletinboard:mybulletinboard:1.0_rc4
-
cpe:2.3:a:mybulletinboard:mybulletinboard:1.1
-
cpe:2.3:a:mybulletinboard:mybulletinboard:1.1.1
-
cpe:2.3:a:mybulletinboard:mybulletinboard:1.1.2
-
cpe:2.3:a:mybulletinboard:mybulletinboard:1.1.3
-
cpe:2.3:a:mybulletinboard:mybulletinboard:1.1.4
-
cpe:2.3:a:mybulletinboard:mybulletinboard:1.1.5
-
cpe:2.3:a:mybulletinboard:mybulletinboard:1.1.7
-
cpe:2.3:a:mybulletinboard:mybulletinboard:1.10
-
cpe:2.3:a:mybulletinboard:mybulletinboard:1.14
-
cpe:2.3:a:mybulletinboard:mybulletinboard:1.20