YaBB 1 SP 1.3.1 displays different error messages when a user exists or not, which makes it easier for remote attackers to identify valid users and conduct a brute force password guessing attack.
References
Configurations
Information
Published : 2004-11-22 21:00
Updated : 2017-07-10 18:30
NVD link : CVE-2004-0294
Mitre link : CVE-2004-0294
JSON object : View
CWE
Products Affected
yabb
- yabb