In MyBB before 1.8.11, the smilie module allows Directory Traversal via the pathfolder parameter.
References
Link Resource
http://seclists.org/fulldisclosure/2017/Apr/55 Exploit Mailing List Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/98045 Third Party Advisory VDB Entry
https://blog.mybb.com/2017/04/04/mybb-1-8-11-merge-system-1-8-11-release/ Patch Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2017-04-24T18:00:00

Updated: 2017-04-28T09:57:01

Reserved: 2017-04-24T00:00:00


Link: CVE-2017-8104

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2017-04-24T18:59:00.867

Modified: 2019-03-19T15:31:43.077


Link: CVE-2017-8104

JSON object: View

cve-icon Redhat Information

No data.

CWE