VulnerabilityModified
CVE-2015-8977
MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allow remote attackers to obtain the installation path via vectors involving error log files.
HIGH 7.5EPSS 2.25%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.25%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allow remote attackers to obtain the installation path via vectors involving error log files.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 2.25% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-532
- Affected
- mybb/merge system · mybb/mybb
- Source
- cve@mitre.org
References
- http://www.openwall.com/lists/oss-security/2016/11/10/8Third Party Advisory
- http://www.openwall.com/lists/oss-security/2016/11/18/1Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/94397Third Party Advisory, VDB Entry
- https://blog.mybb.com/2015/09/07/mybb-1-8-6-1-6-18-merge-system-1-8-6-release/Release Notes, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2016/11/10/8Third Party Advisory
- http://www.openwall.com/lists/oss-security/2016/11/18/1Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/94397Third Party Advisory, VDB Entry
- https://blog.mybb.com/2015/09/07/mybb-1-8-6-1-6-18-merge-system-1-8-6-release/Release Notes, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.