CVE-2012-2327: Infoleak
Published Aug 13, 2012
·Updated
MyBB (aka MyBulletinBoard) before 1.6.7 allows remote attackers to obtain sensitive information via a malformed forumread cookie, which reveals the installation path in an error message.
Affected Software
62 affected components
Mybb Mybb<=1.6.6
Mybb Mybb=1.00
Mybb Mybb=1.0-beta4
Mybb Mybb=1.0-pr1
Mybb Mybb=1.0-pr2
Mybb Mybb=1.0-rc1
Mybb Mybb=1.0-rc2
Mybb Mybb=1.0-rc3
Mybb Mybb=1.0-rc4
Mybb Mybb=1.01
Mybb Mybb=1.1.0
Mybb Mybb=1.1.1
Mybb Mybb=1.1.2
Mybb Mybb=1.1.3
Mybb Mybb=1.1.4
Mybb Mybb=1.1.5
Mybb Mybb=1.1.6
Mybb Mybb=1.1.7
Mybb Mybb=1.1.8
Mybb Mybb=1.02
Mybb Mybb=1.2.0
Mybb Mybb=1.2.1
Mybb Mybb=1.2.2
Mybb Mybb=1.2.3
Mybb Mybb=1.2.4
Mybb Mybb=1.2.5
Mybb Mybb=1.2.6
Mybb Mybb=1.2.7
Mybb Mybb=1.2.8
Mybb Mybb=1.2.9
Mybb Mybb=1.2.10
Mybb Mybb=1.2.11
Mybb Mybb=1.2.12
Mybb Mybb=1.2.13
Mybb Mybb=1.2.14
Mybb Mybb=1.03
Mybb Mybb=1.3-pre-1.0
Mybb Mybb=1.04
Mybb Mybb=1.4.0
Mybb Mybb=1.4.1
Mybb Mybb=1.4.2
Mybb Mybb=1.4.3
Mybb Mybb=1.4.4
Mybb Mybb=1.4.5
Mybb Mybb=1.4.6
Mybb Mybb=1.4.7
Mybb Mybb=1.4.8
Mybb Mybb=1.4.9
Mybb Mybb=1.4.10
Mybb Mybb=1.4.11
Mybb Mybb=1.4.12
Mybb Mybb=1.4.13
Mybb Mybb=1.4.14
Mybb Mybb=1.4.15
Mybb Mybb=1.4.16
Mybb Mybb=1.5.1
Mybb Mybb=1.5.2
Mybb Mybb=1.6.1
Mybb Mybb=1.6.2
Mybb Mybb=1.6.3
Mybb Mybb=1.6.4
Mybb Mybb=1.6.5
Remediation
Event History
Aug 13, 2012
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-2327?
CVE-2012-2327 is rated as medium severity due to it allowing remote attackers to reveal sensitive information.
2
How do I fix CVE-2012-2327?
To fix CVE-2012-2327, upgrade to MyBB version 1.6.7 or later.
3
What versions of MyBB are affected by CVE-2012-2327?
MyBB versions prior to 1.6.7, including 1.6.6 and earlier, are affected by CVE-2012-2327.
4
What type of vulnerability is CVE-2012-2327?
CVE-2012-2327 is a security vulnerability that involves improper validation of input from a malformed forumread cookie.
5
What happens if CVE-2012-2327 is exploited?
If exploited, CVE-2012-2327 could allow an attacker to gain information about the installation path of the MyBB application.