CVE-2016-9417: SSRF
Published Jan 31, 2017
·Updated
The fetchremotefile function in MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 allows remote attackers to conduct server-side request forgery (SSRF) attacks via unspecified vectors.
Affected Software
2 affected components
MyBB Merge System<=1.8.7
MyBB MyBB<=1.8.7
Remediation
Patch Available
Patch Available
Event History
Jan 31, 2017
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Data Sourced
via NVD·10:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-9417?
CVE-2016-9417 has been classified as a medium severity vulnerability due to its potential for server-side request forgery.
2
How do I fix CVE-2016-9417?
To fix CVE-2016-9417, you should upgrade MyBB or MyBB Merge System to version 1.8.8 or later.
3
What vulnerabilities does CVE-2016-9417 exploit?
CVE-2016-9417 exploits the fetch_remote_file function, allowing attackers to carry out server-side request forgery attacks.
4
Which versions of MyBB are affected by CVE-2016-9417?
CVE-2016-9417 affects MyBB versions prior to 1.8.8, including versions up to 1.8.7.
5
Can CVE-2016-9417 be exploited remotely?
Yes, CVE-2016-9417 can be exploited remotely by attackers through specific vectors.