MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allow remote attackers to obtain sensitive information by leveraging missing directory listing protection in upload directories.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/94395 | vdb entry third party advisory |
http://www.openwall.com/lists/oss-security/2016/11/18/1 | mailing list third party advisory patch |
http://www.openwall.com/lists/oss-security/2016/11/10/8 | mailing list third party advisory patch |
https://blog.mybb.com/2016/03/11/mybb-1-8-7-merge-system-1-8-7-release/ | third party advisory patch vendor advisory |