CVE-2015-8977

MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allow remote attackers to obtain the installation path via vectors involving error log files.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mybb:mybb:1.8.5:*:*:*:*:*:*:*
cpe:2.3:a:mybb:mybb:1.8.3:*:*:*:*:*:*:*
cpe:2.3:a:mybb:mybb:1.8.1:*:*:*:*:*:*:*
cpe:2.3:a:mybb:mybb:1.8.0:*:*:*:*:*:*:*
cpe:2.3:a:mybb:mybb:*:*:*:*:*:*:*:*
cpe:2.3:a:mybb:merge_system:*:*:*:*:*:*:*:*
cpe:2.3:a:mybb:mybb:1.8.4:*:*:*:*:*:*:*
cpe:2.3:a:mybb:mybb:1.8.2:*:*:*:*:*:*:*

Information

Published : 2017-01-31 14:59

Updated : 2017-02-05 12:57


NVD link : CVE-2015-8977

Mitre link : CVE-2015-8977


JSON object : View

CWE
CWE-532

Insertion of Sensitive Information into Log File

Advertisement

dedicated server usa

Products Affected

mybb

  • merge_system
  • mybb