search.php in MyBB 1.0.2 allows remote attackers to obtain sensitive information via a certain search request that reveals the table prefix in a SQL error message, possibly due to invalid parameters.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/24272 | vdb entry |
http://secunia.com/advisories/18577 | vendor advisory third party advisory exploit |
http://www.securityfocus.com/archive/1/422227/100/0/threaded | mailing list |
http://www.osvdb.org/22736 | vdb entry |