YABB Unauthorized Access Vulnerability
BID:19366
Info
YABB Unauthorized Access Vulnerability
| Bugtraq ID: | 19366 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 06 2006 12:00AM |
| Updated: | Aug 07 2006 10:56PM |
| Credit: | mkpdev has been credited with the discovery of this vulnerability. |
| Vulnerable: |
YaBB YaBB Y1Gold_Beta7 YaBB YaBB Y1Gold_Beta6 YaBB YaBB 1111-6 YaBB YaBB 1 Gold - SP 1.4 YaBB YaBB 1 Gold - SP 1.3.2 YaBB YaBB 1 Gold - SP 1.3.1 YaBB YaBB 1 Gold - SP 1.3 YaBB YaBB 1 Gold - SP 1.2 YaBB YaBB 1 Gold - SP 1 |
| Not Vulnerable: |
YaBB YaBB 2.1 YaBB YaBB 2.0 |
Discussion
YABB Unauthorized Access Vulnerability
YABB is prone to an unauthorized-access vulnerability because it fails to properly secure sensitive information.
A successful exploit will allow the attacker to gain administrative access and to manipulate sensitive information. Other attacks are also possible.
YABB is prone to an unauthorized-access vulnerability because it fails to properly secure sensitive information.
A successful exploit will allow the attacker to gain administrative access and to manipulate sensitive information. Other attacks are also possible.
Exploit / POC
YABB Unauthorized Access Vulnerability
Attackers can exploit this issue via a web client.
Attackers can exploit this issue via a web client.
Solution / Fix
YABB Unauthorized Access Vulnerability
Solution:
The vendor has released version 2.1 to address this issue. Please see the references for more information.
Solution:
The vendor has released version 2.1 to address this issue. Please see the references for more information.