Логотип exploitDog
bind:CVE-2002-1846
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2002-1846

Количество 2

Количество 2

nvd логотип

CVE-2002-1846

около 23 лет назад

Yet Another Bulletin Board (YaBB) 1.40 and 1.41 does not require a user to submit the correct password before changing it to a new password, which allows remote attackers to modify passwords by stealing the cookie of another user, modifying the expiretime setting, and submitting the change in a profile2 action to index.php.

CVSS2: 5
EPSS: Низкий
github логотип

GHSA-rp5q-5rp7-fg23

почти 4 года назад

Yet Another Bulletin Board (YaBB) 1.40 and 1.41 does not require a user to submit the correct password before changing it to a new password, which allows remote attackers to modify passwords by stealing the cookie of another user, modifying the expiretime setting, and submitting the change in a profile2 action to index.php.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2002-1846

Yet Another Bulletin Board (YaBB) 1.40 and 1.41 does not require a user to submit the correct password before changing it to a new password, which allows remote attackers to modify passwords by stealing the cookie of another user, modifying the expiretime setting, and submitting the change in a profile2 action to index.php.

CVSS2: 5
0%
Низкий
около 23 лет назад
github логотип
GHSA-rp5q-5rp7-fg23

Yet Another Bulletin Board (YaBB) 1.40 and 1.41 does not require a user to submit the correct password before changing it to a new password, which allows remote attackers to modify passwords by stealing the cookie of another user, modifying the expiretime setting, and submitting the change in a profile2 action to index.php.

0%
Низкий
почти 4 года назад

Уязвимостей на страницу