Vulnerabilities > CVE-2007-0689 - Unspecified vulnerability in Mybb
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
MyBB 1.2.4 allows remote attackers to obtain sensitive information via the (1) action[] parameter to member.php, (2) imagehash[] parameter to captcha.php, and (3) a direct request to inc/datahandlers/event.php, which reveal the installation path in the resulting error message.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | Mybb
| 27 |
References
- http://marc.info/?l=full-disclosure&m=117909973216181&w=2
- http://marc.info/?l=full-disclosure&m=117909973216181&w=2
- http://osvdb.org/35548
- http://osvdb.org/35548
- http://osvdb.org/35549
- http://osvdb.org/35549
- http://www.netvigilance.com/advisory0017
- http://www.netvigilance.com/advisory0017
- http://www.osvdb.org/34155
- http://www.osvdb.org/34155
- http://www.securityfocus.com/archive/1/468549/100/0/threaded
- http://www.securityfocus.com/archive/1/468549/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34336
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34336