YaBB 1 SP 1.3.1 displays different error messages when a user exists or not, which makes it easier for remote attackers to identify valid users and conduct a brute force password guessing attack.
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/15236 | vdb entry third party advisory |
http://marc.info/?l=bugtraq&m=107703591314745&w=2 | third party advisory mailing list |
http://www.securityfocus.com/bid/9677 | vendor advisory vdb entry third party advisory broken link |