CVE-2004-0294

YaBB 1 SP 1.3.1 displays different error messages when a user exists or not, which makes it easier for remote attackers to identify valid users and conduct a brute force password guessing attack.
Configurations

Configuration 1 (hide)

cpe:2.3:a:yabb:yabb:1_gold_-_sp_1.3.1:*:*:*:*:*:*:*

Information

Published : 2004-11-23 05:00

Updated : 2017-07-11 01:30


NVD link : CVE-2004-0294

Mitre link : CVE-2004-0294


JSON object : View

Products Affected

yabb

  • yabb