MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to obtain sensitive database information via vectors involving templates.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/94395 | vdb entry third party advisory |
http://www.openwall.com/lists/oss-security/2016/11/18/1 | mailing list third party advisory patch |
http://www.openwall.com/lists/oss-security/2016/11/10/8 | mailing list third party advisory patch |
https://blog.mybb.com/2016/03/11/mybb-1-8-7-merge-system-1-8-7-release/ | third party advisory patch vendor advisory |