Description
MyBB before 1.8.33 allows Directory Traversal. The Admin CP Languages module allows remote authenticated users, with high privileges, to achieve local file inclusion and execution.
Remediation
References
Related Vulnerabilities
PHP Other Vulnerability (CVE-2007-1286)
WordPress Plugin Modern Events Calendar Lite Cross-Site Scripting (5.22.1)
Internet Information Services Other Vulnerability (CVE-2001-0096)
IBM RTC Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2014-3092)
WebLogic Missing Authentication for Critical Function Vulnerability (CVE-2026-35299)