MyBB (aka MyBulletinBoard) before 1.8.8 on Windows and MyBB Merge System before 1.8.8 on Windows allow remote attackers to overwrite arbitrary CSS files via vectors related to "style import."
References
Link | Resource |
---|---|
https://blog.mybb.com/2016/10/17/mybb-1-8-8-merge-system-1-8-8-release/ | Release Notes Vendor Advisory Patch |
http://www.openwall.com/lists/oss-security/2016/11/18/1 | Mailing List Patch Third Party Advisory |
http://www.openwall.com/lists/oss-security/2016/11/10/8 | Mailing List Patch Third Party Advisory |
http://www.securityfocus.com/bid/94396 | Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
AND |
|
History
No history.
Information
Published : 2017-01-31 22:59
Updated : 2017-02-05 21:01
NVD link : CVE-2016-9415
Mitre link : CVE-2016-9415
JSON object : View
Products Affected
mybb
- mybb
- merge_system
microsoft
- windows
CWE
CWE-284
Improper Access Control