MyBB (aka MyBulletinBoard) before 1.8.8 on Windows and MyBB Merge System before 1.8.8 on Windows allow remote attackers to overwrite arbitrary CSS files via vectors related to "style import."
References
Link | Resource |
---|---|
https://blog.mybb.com/2016/10/17/mybb-1-8-8-merge-system-1-8-8-release/ | Release Notes Vendor Advisory Patch |
http://www.openwall.com/lists/oss-security/2016/11/18/1 | Mailing List Patch Third Party Advisory |
http://www.openwall.com/lists/oss-security/2016/11/10/8 | Mailing List Patch Third Party Advisory |
http://www.securityfocus.com/bid/94396 | Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2017-01-31 14:59
Updated : 2017-02-05 13:01
NVD link : CVE-2016-9415
Mitre link : CVE-2016-9415
JSON object : View
CWE
CWE-284
Improper Access Control
Products Affected
mybb
- merge_system
- mybb
microsoft
- windows