vendor:
MyBB
by:
Not available
3,3
CVSS
LOW
Directory Traversal
22 (Path Traversal)
CWE
Product Name: MyBB
Affected Version From: < 1.8.11
Affected Version To: < 1.8.11
Patch Exists: YES
Related CWE: Not available
CPE: a:mybb:mybb
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Not available
2017
MyBB Directory Traversal Vulnerability
A Directory Traversal vulnerability was discovered in MyBB version < 1.8.11. The vulnerability exists in the 'pathfolder' parameter of the '/webroot/mybb_1810/Upload/admin/modules/config/smilies.php' file. By setting the 'pathfolder' parameter to '../../bypass/smile', an attacker can traverse the directory and access sensitive information.
Mitigation:
Upgrade to MyBB version 1.8.11