MyBB (aka MyBulletinBoard) before 1.8.8 on Windows and MyBB Merge System before 1.8.8 on Windows allow remote attackers to overwrite arbitrary CSS files via vectors related to "style import."
References
Link | Resource |
---|---|
http://www.openwall.com/lists/oss-security/2016/11/10/8 | Mailing List Patch Third Party Advisory |
http://www.openwall.com/lists/oss-security/2016/11/18/1 | Mailing List Patch Third Party Advisory |
http://www.securityfocus.com/bid/94396 | Third Party Advisory VDB Entry |
https://blog.mybb.com/2016/10/17/mybb-1-8-8-merge-system-1-8-8-release/ | Release Notes Vendor Advisory Patch |
Configurations
Configuration 1 (hide)
AND |
|
History
No history.
Information
Published : 2017-01-31 22:59
Updated : 2017-02-05 21:01
NVD link : CVE-2016-9415
Mitre link : CVE-2016-9415
CVE.ORG link : CVE-2016-9415
JSON object : View
Products Affected
mybb
- merge_system
- mybb
microsoft
- windows
CWE
CWE-284
Improper Access Control