MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allow attackers to have unspecified impact via vectors related to low adminsid and sid entropy.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/94395 | vdb entry third party advisory |
http://www.openwall.com/lists/oss-security/2016/11/18/1 | mailing list third party advisory patch |
http://www.openwall.com/lists/oss-security/2016/11/10/8 | mailing list third party advisory patch |
https://blog.mybb.com/2016/03/11/mybb-1-8-7-merge-system-1-8-7-release/ | release notes patch vendor advisory |