CVE-2007-0689: Medium severity Mybb Mybb vulnerability
Published May 14, 2007
·Updated
MyBB 1.2.4 allows remote attackers to obtain sensitive information via the (1) action[] parameter to member.php, (2) imagehash[] parameter to captcha.php, and (3) a direct request to inc/datahandlers/event.php, which reveal the installation path in the resulting error message.
Affected Software
1 affected component
Mybb Mybb<=1.2.4
Event History
May 14, 2007
CVE Published
09:19 PM
May 15, 2007
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-0689?
CVE-2007-0689 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2007-0689?
To mitigate CVE-2007-0689, upgrade MyBB to a version later than 1.2.4.
3
What information can be leaked due to CVE-2007-0689?
CVE-2007-0689 can expose the installation path of the MyBB application.
4
Which versions of MyBB are affected by CVE-2007-0689?
CVE-2007-0689 affects MyBB version 1.2.4 and earlier.
5
What are the entry points for exploitation of CVE-2007-0689?
CVE-2007-0689 can be exploited through the action[] parameter in member.php, imagehash[] parameter in captcha.php, or a direct request to inc/datahandlers/event.php.