Directory traversal vulnerability in MyBB (aka MyBulletinBoard) 1.02 allows local users with MyBB administrative privileges to include and possibly execute arbitrary local files via directory traversal sequences and a nul (%00) character in the plugin parameter.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/423465/100/0/threaded | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/24461 | vdb entry |