PT-2007-2143 · Mybb · Mybb

Publicado

2007-05-14

·

Atualizado

2018-10-16

·

CVE-2007-0689

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions MyBB version 1.2.4
Description The issue allows remote attackers to obtain sensitive information. This can be achieved via the action[] parameter to "member.php", the imagehash[] parameter to "captcha.php", and a direct request to "inc/datahandlers/event.php". These actions reveal the installation path in the resulting error message.
Recommendations For MyBB version 1.2.4, consider restricting access to the "member.php" and "captcha.php" scripts, and avoid direct requests to "inc/datahandlers/event.php" until a fix is available. As a temporary workaround, consider modifying the error handling in "inc/datahandlers/event.php" to prevent the disclosure of sensitive information.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-0689

Produtos afetados

Mybb