|
264721
|
5.3 |
MEDIUM
Network
|
mybb
|
mybb merge_system
|
The Admin control panel in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allows remote attackers to obtain the installation path via vectors involving sending mails.
|
CWE-200
Information Exposure
|
CVE-2016-9411
|
2024-11-21 12:01 |
2017-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264722
|
7.5 |
HIGH
Network
|
mybb
|
mybb merge_system
|
MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to obtain sensitive database information via vectors involving templates.
|
CWE-200
Information Exposure
|
CVE-2016-9410
|
2024-11-21 12:01 |
2017-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264723
|
6.1 |
MEDIUM
Network
|
mybb
|
mybb merge_system
|
Cross-site scripting (XSS) vulnerability in the Admin control panel in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web …
|
CWE-79
Cross-site Scripting
|
CVE-2016-9409
|
2024-11-21 12:01 |
2017-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264724
|
6.1 |
MEDIUM
Network
|
mybb
|
mybb merge_system
|
Cross-site scripting (XSS) vulnerability in the Mod control panel in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web sc…
|
CWE-79
Cross-site Scripting
|
CVE-2016-9408
|
2024-11-21 12:01 |
2017-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264725
|
6.1 |
MEDIUM
Network
|
mybb
|
mybb merge_system
|
Cross-site scripting (XSS) vulnerability in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script or HTML via vectors …
|
CWE-79
Cross-site Scripting
|
CVE-2016-9407
|
2024-11-21 12:01 |
2017-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264726
|
6.1 |
MEDIUM
Network
|
mybb
|
mybb merge_system
|
Cross-site scripting (XSS) vulnerability in the User control panel in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web s…
|
CWE-79
Cross-site Scripting
|
CVE-2016-9406
|
2024-11-21 12:01 |
2017-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264727
|
6.1 |
MEDIUM
Network
|
mybb
|
mybb merge_system
|
Cross-site scripting (XSS) vulnerability in member validation in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script…
|
CWE-79
Cross-site Scripting
|
CVE-2016-9405
|
2024-11-21 12:01 |
2017-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264728
|
6.1 |
MEDIUM
Network
|
mybb
|
mybb merge_system
|
Cross-site scripting (XSS) vulnerability in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script or HTML via vectors …
|
CWE-79
Cross-site Scripting
|
CVE-2016-9404
|
2024-11-21 12:01 |
2017-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264729
|
9.8 |
CRITICAL
Network
|
mybb
|
mybb merge_system
|
newreply.php in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allows remote attackers to have unspecified impact by leveraging a missing permission check.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-9403
|
2024-11-21 12:01 |
2017-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264730
|
9.8 |
CRITICAL
Network
|
mybb
|
mybb merge_system
|
SQL injection vulnerability in the moderation tool in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to execute arbitrary SQL commands via uns…
|
CWE-89
SQL Injection
|
CVE-2016-9402
|
2024-11-21 12:01 |
2017-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|