7.5

CVE-2015-8977

MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allow remote attackers to obtain the installation path via vectors involving error log files.

Data is provided by the National Vulnerability Database (NVD)
MybbMerge System Version <= 1.8.5
MybbMybb Version <= 1.6.17
MybbMybb Version1.8.0
MybbMybb Version1.8.1
MybbMybb Version1.8.2
MybbMybb Version1.8.3
MybbMybb Version1.8.4
MybbMybb Version1.8.5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.22% 0.771
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-532 Insertion of Sensitive Information into Log File

The product writes sensitive information to a log file.