YaBB SE Cookie Security Bypass Vulnerability
BID:27414
Info
YaBB SE Cookie Security Bypass Vulnerability
| Bugtraq ID: | 27414 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 22 2008 12:00AM |
| Updated: | Jan 23 2008 10:38PM |
| Credit: | 1dt.w0lf discovered this vulnerability. |
| Vulnerable: |
YaBB SE YaBB SE 1.5.5 b YaBB SE YaBB SE 1.5.5 YaBB SE YaBB SE 1.5.4 YaBB SE YaBB SE 1.5.3 YaBB SE YaBB SE 1.5.2 YaBB SE YaBB SE 1.5.1 YaBB SE YaBB SE 1.5 .1 RC1 YaBB SE YaBB SE 1.5 .0 |
| Not Vulnerable: | |
Discussion
YaBB SE Cookie Security Bypass Vulnerability
YaBB SE is prone to a security-bypass vulnerability because it fails to properly validate user credentials before performing certain actions.
Exploiting this issue may allow an attacker to obtain sensitive information, compromise the application, and execute arbitrary script code in the context of webserver process; other attacks are also possible.
This issue affects YaBB SE 1.5.5 and prior versions.
YaBB SE is prone to a security-bypass vulnerability because it fails to properly validate user credentials before performing certain actions.
Exploiting this issue may allow an attacker to obtain sensitive information, compromise the application, and execute arbitrary script code in the context of webserver process; other attacks are also possible.
This issue affects YaBB SE 1.5.5 and prior versions.
Exploit / POC
YaBB SE Cookie Security Bypass Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
YaBB SE Cookie Security Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].