|
YaBB Information Leakage Weakness
YaBB is prone to a weakness that may permit remote users to enumerate usernames. This could aid in further attacks. It should be noted that this issue would only present a security risk on installations that do not allow guests or anonymous web users to browse the forum, in which case remote users would not be privy to usernames. This issue was reported in YaBB 1 Gold - SP 1.3.1. Other versions may also be affected. |
|
|
Privacy Statement |