YaBB Information Leakage Weakness
BID:9677
Info
YaBB Information Leakage Weakness
| Bugtraq ID: | 9677 |
| Class: | Design Error |
| CVE: |
CVE-2004-0294 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 17 2004 12:00AM |
| Updated: | Jul 12 2009 03:06AM |
| Credit: | Discovery is credited to David Cantrell. |
| Vulnerable: |
YaBB YaBB 1 Gold - SP 1.3.1 |
| Not Vulnerable: | |
Discussion
YaBB Information Leakage Weakness
YaBB is prone to a weakness that may permit remote users to enumerate usernames. This could aid in further attacks.
It should be noted that this issue would only present a security risk on installations that do not allow guests or anonymous web users to browse the forum, in which case remote users would not be privy to usernames.
This issue was reported in YaBB 1 Gold - SP 1.3.1. Other versions may also be affected.
YaBB is prone to a weakness that may permit remote users to enumerate usernames. This could aid in further attacks.
It should be noted that this issue would only present a security risk on installations that do not allow guests or anonymous web users to browse the forum, in which case remote users would not be privy to usernames.
This issue was reported in YaBB 1 Gold - SP 1.3.1. Other versions may also be affected.
Exploit / POC
YaBB Information Leakage Weakness
There is no exploit required.
There is no exploit required.
Solution / Fix
YaBB Information Leakage Weakness
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
YaBB Information Leakage Weakness
References:
References:
- YaBB Homepage (YaBB)
- YABB information leakage on failed login (David Cantrell
)