← Back

CVE-2007-1964

nvd nist
Published: Apr 11, 2007Modified: Apr 23, 2026

JSON object

Loading...
6.0
Vector
AV:N/AC:M/Au:S/C:P/I:P/A:P
Exploitability: 6.8 / Impact: 6.4
Source: NVD

Description

member.php in MyBB (aka MyBulletinBoard), when debug mode is available, allows remote authenticated users to change the password of any account by providing the account's registered e-mail address in a debug request for a do_lostpw action, which prints the change password verification code in the debug output.

Affected (2)

1 product
Mybb
Mybulletinboard
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Version 1.2.5
Version 1.2.5

Timeline

No history available yet.