Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
member.php in MyBB (aka MyBulletinBoard) before 1.4.12 makes a certain superfluous call to the SQL COUNT function, which allows remote attackers to cause a denial of service (resource consumption) by making requests to member.php that trigger scans of the entire users table.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
MyBB member.php文件拒绝服务漏洞
Vulnerability Description
MyBB(又名MyBulletinBoard)是MyBB团队开发的一套用PHP和MySQL开发的免费且基于Web的论坛软件。该软件具有简单易用、支持多国语言、可扩展等特点。 MyBB(又名MyBulletinBoard)1.4.12之前版本中的member.php文件对SQL COUNT函数的过度调用。远程攻击者可以通过建立能够触发对整个用户表扫描的member.php文件的请求导致拒绝服务(资源消耗)。
CVSS Information
N/A
Vulnerability Type
N/A