Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The fetch_remote_file function in MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 allows remote attackers to conduct server-side request forgery (SSRF) attacks via unspecified vectors.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
MyBB和MyBB Merge System 安全漏洞
Vulnerability Description
MyBB(又名MyBulletinBoard)和MyBB Merge System都是MyBB团队开发的产品。前者是一套用PHP和MySQL开发的免费且基于Web的论坛软件,后者是一套用于将现有论坛或者其他论坛合并到MyBB论坛的工具。 MyBB 1.8.7及之前的版本和MyBB Merge System 1.8.7及之前的版本中的‘fetch_remote_file’函数存在服务器端请求伪造漏洞。远程攻击者可利用该漏洞执行未授权的操作。
CVSS Information
N/A
Vulnerability Type
N/A