YaBB SE Cookie Security Bypass Vulnerability

YaBB SE is prone to a security-bypass vulnerability because it fails to properly validate user credentials before performing certain actions.

Exploiting this issue may allow an attacker to obtain sensitive information, compromise the application, and execute arbitrary script code in the context of webserver process; other attacks are also possible.

This issue affects YaBB SE 1.5.5 and prior versions.


 

Privacy Statement
Copyright 2010, SecurityFocus