Yet Another Bulletin Board (YaBB)

漏洞信息详情

Yet Another Bulletin Board (YaBB)

漏洞简介

Yet Another Bulletin Board (YaBB) 1.40和 1.41版本在更改为新密码之前不需要用户提交正确密码。远程攻击者通过盗用其他用户的cookie,修改expiretime设置以及将profile2作用的改变提交给index.php从而修改密码。

漏洞公告

参考网址

Vulnerable software and versionsConfiguration 1OR* cpe:/a:yabb:yabb:1.40* cpe:/a:yabb:yabb:1.41* Denotes Vulnerable Software* Changes related to vulnerability configurations

Technical DetailsVulnerability Type (View All)
CVE Standard Vulnerability Entry:http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1846

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享