CVE-2002-0903: High severity WoltLab Burning Board vulnerability
register.php for WoltLab Burning Board (wbboard) 1.1.1 uses a small number of random values for the "code" parameter that is provided to action.php to approve a new registration, along with predictable new user ID's, which allows remote attackers to hijack new user accounts via a brute force attack on the new user ID and the code value.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2002-0903?
CVE-2002-0903 is considered a medium severity vulnerability due to the potential for account hijacking.
How do I fix CVE-2002-0903?
To fix CVE-2002-0903, it is recommended to upgrade to a newer version of WoltLab Burning Board that addresses this vulnerability.
What types of attacks does CVE-2002-0903 facilitate?
CVE-2002-0903 facilitates brute force attacks that can lead to the hijacking of new user accounts.
Which version of WoltLab Burning Board is affected by CVE-2002-0903?
Only WoltLab Burning Board version 1.1.1 is affected by CVE-2002-0903.
Can CVE-2002-0903 be exploited by unauthenticated users?
Yes, CVE-2002-0903 can be exploited by unauthenticated remote attackers.