Описание
YaBB 1 SP 1.3.1 displays different error messages when a user exists or not, which makes it easier for remote attackers to identify valid users and conduct a brute force password guessing attack.
Ссылки
- Third Party Advisory
- Broken LinkThird Party AdvisoryVDB EntryVendor Advisory
- Third Party AdvisoryVDB Entry
- Third Party Advisory
- Broken LinkThird Party AdvisoryVDB EntryVendor Advisory
- Third Party AdvisoryVDB Entry
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:yabbforumsoftware:yet_another_bulletin_board:1.0:sp1.3.1:*:*:*:*:*:*
EPSS
Процентиль: 83%
0.0205
Низкий
5 Medium
CVSS2
Дефекты
CWE-203
Связанные уязвимости
github
почти 4 года назад
YaBB 1 SP 1.3.1 displays different error messages when a user exists or not, which makes it easier for remote attackers to identify valid users and conduct a brute force password guessing attack.
EPSS
Процентиль: 83%
0.0205
Низкий
5 Medium
CVSS2
Дефекты
CWE-203