The Admin control panel in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allows remote attackers to obtain the installation path via vectors involving sending mails.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/94395 | third party advisory vdb entry |
http://www.openwall.com/lists/oss-security/2016/11/18/1 | patch mailing list third party advisory |
http://www.openwall.com/lists/oss-security/2016/11/10/8 | patch mailing list third party advisory |
https://blog.mybb.com/2016/03/11/mybb-1-8-7-merge-system-1-8-7-release/ | patch vendor advisory release notes |