MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allow remote attackers to obtain the installation path via vectors involving error log files.
References
| Link | Resource |
|---|---|
| http://www.openwall.com/lists/oss-security/2016/11/10/8 | Third Party Advisory |
| http://www.openwall.com/lists/oss-security/2016/11/18/1 | Mailing List Third Party Advisory |
| http://www.securityfocus.com/bid/94397 | Third Party Advisory VDB Entry |
| https://blog.mybb.com/2015/09/07/mybb-1-8-6-1-6-18-merge-system-1-8-6-release/ | Release Notes Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2016/11/10/8 | Third Party Advisory |
| http://www.openwall.com/lists/oss-security/2016/11/18/1 | Mailing List Third Party Advisory |
| http://www.securityfocus.com/bid/94397 | Third Party Advisory VDB Entry |
| https://blog.mybb.com/2015/09/07/mybb-1-8-6-1-6-18-merge-system-1-8-6-release/ | Release Notes Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 02:39
| Type | Values Removed | Values Added |
|---|---|---|
| References | () http://www.openwall.com/lists/oss-security/2016/11/10/8 - Third Party Advisory | |
| References | () http://www.openwall.com/lists/oss-security/2016/11/18/1 - Mailing List, Third Party Advisory | |
| References | () http://www.securityfocus.com/bid/94397 - Third Party Advisory, VDB Entry | |
| References | () https://blog.mybb.com/2015/09/07/mybb-1-8-6-1-6-18-merge-system-1-8-6-release/ - Release Notes, Vendor Advisory |
Information
Published : 2017-01-31 22:59
Updated : 2025-04-20 01:37
NVD link : CVE-2015-8977
Mitre link : CVE-2015-8977
CVE.ORG link : CVE-2015-8977
JSON object : View
Products Affected
mybb
- merge_system
- mybb
CWE
CWE-532
Insertion of Sensitive Information into Log File
