MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allow remote attackers to obtain the installation path via vectors involving error log files.
The product writes sensitive information to a log file.
Link | Tags |
---|---|
https://blog.mybb.com/2015/09/07/mybb-1-8-6-1-6-18-merge-system-1-8-6-release/ | release notes vendor advisory |
http://www.securityfocus.com/bid/94397 | vdb entry third party advisory |
http://www.openwall.com/lists/oss-security/2016/11/18/1 | third party advisory mailing list |
http://www.openwall.com/lists/oss-security/2016/11/10/8 | third party advisory mailing list |