First published: Wed Aug 25 2004(Updated: )
YaBB SE 1.5.1 allows remote attackers to obtain sensitive information via a direct HTTP request to Admin.php, which reveals the full path in a PHP error message.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Yabb | =1.5.1 | |
Yabb | =1.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1662 is classified as a medium severity vulnerability due to the potential exposure of sensitive information.
To fix CVE-2004-1662, you should upgrade YaBB SE to a more secure version that does not expose the Admin.php file.
CVE-2004-1662 is an information disclosure vulnerability that allows remote attackers to retrieve sensitive path information.
The impact of CVE-2004-1662 is that it may allow attackers to reconnaissance the file structure of the server hosting YaBB SE.
CVE-2004-1662 affects users running YaBB SE version 1.5.1, particularly those who have not secured access to Admin.php.