Back to search
CVE-2004-0294
Published: Mar 18, 2004
Modified: Aug 8, 2024
PUBLISHED
Description
YaBB 1 SP 1.3.1 displays different error messages when a user exists or not, which makes it easier for remote attackers to identify valid users and conduct a brute force password guessing attack.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
yabb-invalidmessage-obtain-information(15236)
vdb-entry
x_refsource_XF
20040217 YABB information leakage on failed login
mailing-list
x_refsource_BUGTRAQ
9677
vdb-entry
x_refsource_BID
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now