YaBB Bulletin Board Corruption Vulnerability
BID:10263
Info
YaBB Bulletin Board Corruption Vulnerability
| Bugtraq ID: | 10263 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 03 2004 12:00AM |
| Updated: | May 03 2004 12:00AM |
| Credit: | Disclosure of this issue is credited to Dmitry Shurupov <[email protected]>. |
| Vulnerable: |
YaBB YaBB 1 Gold - SP 1.2 YaBB YaBB 1 Gold - SP 1 |
| Not Vulnerable: | |
Discussion
YaBB Bulletin Board Corruption Vulnerability
It has been reported that YaBB is affected by a bulletin board corruption vulnerability. This is due to an input validation issue that allows users to specify arbitrary values in a text file associated with the application.
This issue might cause the bulletin board related to the application to become corrupted and unreadable, denying service to legitimate users. Other attacks might also be possible.
It has been reported that YaBB is affected by a bulletin board corruption vulnerability. This is due to an input validation issue that allows users to specify arbitrary values in a text file associated with the application.
This issue might cause the bulletin board related to the application to become corrupted and unreadable, denying service to legitimate users. Other attacks might also be possible.
Exploit / POC
YaBB Bulletin Board Corruption Vulnerability
No exploit is required to leverage this issue.
No exploit is required to leverage this issue.
Solution / Fix
YaBB Bulletin Board Corruption Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
YaBB Bulletin Board Corruption Vulnerability
References:
References:
- Vulnerability in YaBB forum (Perl version without SQL) (Dmitry Shurupov
)