PT-2008-4498 · Mybb · Mybb

Ostro

·

Published

2008-07-08

·

Updated

2012-11-27

·

CVE-2008-3071

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: MyBB versions prior to 1.2.13
Description: The issue is related to a directory traversal vulnerability in the inc/class language.php file, which is associated with the $language variable. The impact and attack vectors of this issue are not specified.
Recommendations: For versions prior to 1.2.13, update to version 1.2.13 or later to resolve the issue. As a temporary workaround, consider restricting access to the inc/class language.php file until a patch is applied. Avoid using the $language variable in sensitive operations until the issue is resolved.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-3071

Affected Products

Mybb