PT-2004-1448 · Yabb · Yabb

·

CVE-2004-0294

·

Published

2004-03-18

·

Updated

2025-05-08

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions YaBB version 1 SP 1.3.1
Description The issue allows remote attackers to identify valid users due to different error messages being displayed when a user exists or not. This makes it easier to conduct a brute force password guessing attack.
Recommendations For YaBB version 1 SP 1.3.1, consider modifying the error messages to be generic, avoiding the disclosure of user existence, until a patch is available. As a temporary workaround, restrict access to the user login functionality to minimize the risk of exploitation.

Fix

Side Channel Attack

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2004-0294

Affected Products

Yabb