CVE-2009-4448

Severity CVSS v4.0:
Pending analysis
Type:
CWE-399 Resource Management Errors
Publication date:
29/12/2009
Last modified:
26/09/2025

Description

inc/functions_time.php in MyBB (aka MyBulletinBoard) 1.4.10, and possibly earlier versions, allows remote attackers to cause a denial of service (CPU consumption) via a crafted request with a large year value, which triggers a long loop, as reachable through member.php and possibly other vectors.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mybb:mybb:1.4.10:*:*:*:*:*:*:*