← Back

CVE-2010-4626

nvd nist
Published: Dec 30, 2010Modified: Apr 29, 2026

JSON object

Loading...
5.1
Vector
AV:N/AC:H/Au:N/C:P/I:P/A:P
Exploitability: 4.9 / Impact: 6.4
Source: NVD

Description

The my_rand function in functions.php in MyBB (aka MyBulletinBoard) before 1.4.12 does not properly use the PHP mt_rand function, which makes it easier for remote attackers to obtain access to an arbitrary account by requesting a reset of the account's password, and then conducting a brute-force attack.

Affected (37)

Products: Mybb: Mybb
1 product
Mybb
Configuration A
37 vulnerable
Vulnerable SoftwareAffected Versions
Mybb
Up to 1.4.11
Version 1.00
Version 1.01
Version 1.02
Version 1.03
Version 1.04
Version 1.1.0
Version 1.1.1
Version 1.1.2
Version 1.1.3
Version 1.1.4
Version 1.1.5
Version 1.1.6
Version 1.1.7
Version 1.1.8
Version 1.2.0
Version 1.2.10
Version 1.2.11
Version 1.2.12
Version 1.2.13
Version 1.2.1
Version 1.2.2
Version 1.2.3
Version 1.2.4
Version 1.2.5
Version 1.2.6
Version 1.2.7
Version 1.2.8
Version 1.2.9
Version 1.2
Version 1.4.0
Version 1.4.10
Version 1.4.2
Version 1.4.3
Version 1.4.6
Version 1.4.8
Version 1.4.9

Related CWEs

Timeline

No history available yet.