MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allow remote attackers to obtain the installation path via vectors involving error log files.
References
| Link | Resource |
|---|---|
| http://www.openwall.com/lists/oss-security/2016/11/10/8 | Third Party Advisory |
| http://www.openwall.com/lists/oss-security/2016/11/18/1 | Mailing List Third Party Advisory |
| http://www.securityfocus.com/bid/94397 | Third Party Advisory VDB Entry |
| https://blog.mybb.com/2015/09/07/mybb-1-8-6-1-6-18-merge-system-1-8-6-release/ | Release Notes Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2016/11/10/8 | Third Party Advisory |
| http://www.openwall.com/lists/oss-security/2016/11/18/1 | Mailing List Third Party Advisory |
| http://www.securityfocus.com/bid/94397 | Third Party Advisory VDB Entry |
| https://blog.mybb.com/2015/09/07/mybb-1-8-6-1-6-18-merge-system-1-8-6-release/ | Release Notes Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2017-01-31 22:59
Updated : 2025-04-20 01:37
NVD link : CVE-2015-8977
Mitre link : CVE-2015-8977
CVE.ORG link : CVE-2015-8977
JSON object : View
Products Affected
mybb
- merge_system
- mybb
CWE
CWE-532
Insertion of Sensitive Information into Log File
