CVE-2016-9411

The Admin control panel in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allows remote attackers to obtain the installation path via vectors involving sending mails.
References
Link Resource
https://blog.mybb.com/2016/03/11/mybb-1-8-7-merge-system-1-8-7-release/ Release Notes Patch Vendor Advisory
http://www.openwall.com/lists/oss-security/2016/11/18/1 Mailing List Patch Third Party Advisory
http://www.openwall.com/lists/oss-security/2016/11/10/8 Mailing List Patch Third Party Advisory
http://www.securityfocus.com/bid/94395 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mybb:mybb:*:*:*:*:*:*:*:*
cpe:2.3:a:mybb:merge_system:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2017-01-31 22:59

Updated : 2017-02-05 21:12


NVD link : CVE-2016-9411

Mitre link : CVE-2016-9411


JSON object : View

Products Affected

mybb

  • mybb
  • merge_system
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor