PT-2002-2568 · Yet Another Bulletin Board · Yabb

Published

2002-12-31

·

Updated

2008-09-05

·

CVE-2002-1846

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Yet Another Bulletin Board (YaBB) versions 1.40 through 1.41
Description The issue allows remote attackers to modify passwords without submitting the correct password. This can be achieved by stealing the cookie of another user, modifying the expiretime setting, and submitting the change in a "profile2" action to "index.php".
Recommendations For versions 1.40 and 1.41, consider temporarily restricting access to the password change functionality until a proper fix is implemented. As a mitigation measure, restrict the ability to submit changes to the "profile2" action in "index.php" to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-1846

Affected Products

Yabb