Open Bulletin Board (OpenBB) 1.0.8 allows remote attackers to obtain the full path of the web server via an invalid pforums parameter to (1) misc.php and (2) member.php.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Open_bulletin_board |
Devsyn |
1.0.8 (including) |
1.0.8 (including) |
References