PT-2002-2568 · Yet Another Bulletin Board · Yabb
Published
2002-12-31
·
Updated
2008-09-05
·
CVE-2002-1846
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Yet Another Bulletin Board (YaBB) versions 1.40 through 1.41
Description
The issue allows remote attackers to modify passwords without submitting the correct password. This can be achieved by stealing the cookie of another user, modifying the
expiretime setting, and submitting the change in a "profile2" action to "index.php".Recommendations
For versions 1.40 and 1.41, consider temporarily restricting access to the password change functionality until a proper fix is implemented. As a mitigation measure, restrict the ability to submit changes to the "profile2" action in "index.php" to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Yabb