Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
MyBB 1.2.4 allows remote attackers to obtain sensitive information via the (1) action[] parameter to member.php, (2) imagehash[] parameter to captcha.php, and (3) a direct request to inc/datahandlers/event.php, which reveal the installation path in the resulting error message.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
MyBB version 'member.php' 多路径破解漏洞
Vulnerability Description
MyBB 允许远程攻击者借助提交到member.php的(1)action[]参数、到captcha.php的(2)imagehash[]参数和到inc/datahandlers/event.php的(3)一个直接请求,获得敏感信息。它会在错误信息中显示安装路径。
CVSS Information
N/A
Vulnerability Type
N/A