MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allow remote attackers to obtain the installation path via vectors involving error log files.
The product writes sensitive information to a log file.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Merge_system | Mybb | * | 1.8.5 (including) |
Mybb | Mybb | * | 1.6.17 (including) |
Mybb | Mybb | 1.8.0 (including) | 1.8.0 (including) |
Mybb | Mybb | 1.8.1 (including) | 1.8.1 (including) |
Mybb | Mybb | 1.8.2 (including) | 1.8.2 (including) |
Mybb | Mybb | 1.8.3 (including) | 1.8.3 (including) |
Mybb | Mybb | 1.8.4 (including) | 1.8.4 (including) |
Mybb | Mybb | 1.8.5 (including) | 1.8.5 (including) |