Nytro Posted December 20, 2012 Report Posted December 20, 2012 [h=2]MyBB 1.6.9 full path disclosure[/h]MyBB has released its update on 15th December. MyBB 1.6.9 is still affected with full path disclosure vulnerablityauthor : cyb3rboywebsite: freemium-devils.incode104.netgreetz cyberace, ketan , shubham , S3v3n , th3 d3stroyer , amolthe following path was found vulnerable to full path disclosure/inc/3rdparty/diff/Diff/Engine/xdiff.php/inc/3rdparty/diff/Diff/Engine/native.php/inc/3rdparty/diff/Diff/ThreeWay.php/inc/3rdparty/diff/Diff/Renderer.php/inc/3rdparty/diff/Diff/Mapped.phphttp://netsoccer.eu/forum/inc/3rdparty/diff/Diff/Engine/xdiff.phphttp://netsoccer.eu/forum/inc/3rdparty/diff/Diff/Engine/native.phphttp://netsoccer.eu/forum//inc/3rdparty/diff/Diff/ThreeWay.phphttp://netsoccer.eu/forum/inc/3rdparty/diff/Diff/Renderer.phphttp://netsoccer.eu/forum/inc/3rdparty/diff/Diff/Mapped.phphttp://shark007.net/forum/inc/3rdparty/diff/Diff/ThreeWay.phphttp://shark007.net/forum//inc/3rdparty/diff/Diff/Mapped.phphttp://www.mybbgm.com/inc/3rdparty/diff/Diff/Mapped.phphttp://www.mybbgm.com/inc/3rdparty/diff/Diff/ThreeWay.php# 1337day.com [2012-12-20]Sursa: 1337day Inj3ct0r Exploit Database : vulnerability : 0day : shellcode by Inj3ct0r Team Quote