CVE-2004-1662: Medium severity Yabb Yabb vulnerability
YaBB SE 1.5.1 allows remote attackers to obtain sensitive information via a direct HTTP request to Admin.php, which reveals the full path in a PHP error message.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1662?
CVE-2004-1662 is classified as a medium severity vulnerability due to the potential exposure of sensitive information.
How do I fix CVE-2004-1662?
To fix CVE-2004-1662, you should upgrade YaBB SE to a more secure version that does not expose the Admin.php file.
What type of vulnerability is CVE-2004-1662?
CVE-2004-1662 is an information disclosure vulnerability that allows remote attackers to retrieve sensitive path information.
What is the impact of CVE-2004-1662?
The impact of CVE-2004-1662 is that it may allow attackers to reconnaissance the file structure of the server hosting YaBB SE.
Who is affected by CVE-2004-1662?
CVE-2004-1662 affects users running YaBB SE version 1.5.1, particularly those who have not secured access to Admin.php.