Open Bulletin Board (OpenBB) 1.0.8 allows remote attackers to obtain the full path of the web server via an invalid pforums parameter to (1) misc.php and (2) member.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Open_bulletin_board | Devsyn | 1.0.8 (including) | 1.0.8 (including) |