VYPR
High severity7.5NVD Advisory· Published Jan 31, 2017· Updated May 13, 2026

CVE-2015-8977

CVE-2015-8977

Description

MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allow remote attackers to obtain the installation path via vectors involving error log files.

Affected products

8
  • cpe:2.3:a:mybb:merge_system:*:*:*:*:*:*:*:*
    Range: <=1.8.5
  • MyBB/Mybb7 versions
    cpe:2.3:a:mybb:mybb:*:*:*:*:*:*:*:*+ 6 more
    • cpe:2.3:a:mybb:mybb:*:*:*:*:*:*:*:*range: <=1.6.17
    • cpe:2.3:a:mybb:mybb:1.8.0:*:*:*:*:*:*:*
    • cpe:2.3:a:mybb:mybb:1.8.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mybb:mybb:1.8.2:*:*:*:*:*:*:*
    • cpe:2.3:a:mybb:mybb:1.8.3:*:*:*:*:*:*:*
    • cpe:2.3:a:mybb:mybb:1.8.4:*:*:*:*:*:*:*
    • cpe:2.3:a:mybb:mybb:1.8.5:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.