Security Advisory
CVE-2012-2327
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
MyBB (aka MyBulletinBoard) before 1.6.7 allows remote attackers to obtain sensitive information via a malformed forumread cookie, which reveals the installation path in an error message.