CVE-2016-9412: Critical severity MyBB Merge System vulnerability
Published Jan 31, 2017
·Updated
MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allow attackers to have unspecified impact via vectors related to low adminsid and sid entropy.
Affected Software
2 affected components
MyBB Merge System<=1.8.6
MyBB MyBB<=1.8.6
Remediation
Patch Available
Patch Available
Event History
Jan 31, 2017
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Data Sourced
via NVD·10:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-9412?
CVE-2016-9412 is regarded as having unspecified impact due to low entropy in admin and session identifiers.
2
How do I fix CVE-2016-9412?
To fix CVE-2016-9412, upgrade MyBB or MyBB Merge System to version 1.8.7 or later.
3
What software is affected by CVE-2016-9412?
CVE-2016-9412 affects MyBB versions before 1.8.7 and MyBB Merge System versions prior to 1.8.7.
4
What type of vulnerability is CVE-2016-9412?
CVE-2016-9412 is a vulnerability related to low entropy in session and admin identifiers.
5
Who reports vulnerabilities like CVE-2016-9412?
Vulnerabilities like CVE-2016-9412 are typically reported by security researchers and organizations in the field of cybersecurity.