CVE-2004-0294: Medium severity Yabbforumsoftware Yet Another Bulletin Board vulnerability
YaBB 1 SP 1.3.1 displays different error messages when a user exists or not, which makes it easier for remote attackers to identify valid users and conduct a brute force password guessing attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0294?
CVE-2004-0294 is considered a medium severity vulnerability as it allows attackers to identify valid usernames for brute force attacks.
How do I fix CVE-2004-0294?
To fix CVE-2004-0294, update to a version of YaBB that does not disclose differing error messages based on valid users.
What systems are affected by CVE-2004-0294?
CVE-2004-0294 affects YaBB versions 1 Gold - SP 1.3.1 and Yet Another Bulletin Board version 1.0 - SP 1.3.1.
What type of attack can CVE-2004-0294 facilitate?
CVE-2004-0294 can facilitate brute force password guessing attacks due to its ability to reveal valid usernames.
Is CVE-2004-0294 still relevant today?
While CVE-2004-0294 is an older vulnerability, systems still using the affected versions remain at risk.