关键漏洞信息 CVE编号: CVE-2004-2402 CVSS v2.0 Base Score: 2.8 CVSS 2.0矢量: - Access Vector: Remote - Access Complexity: High - Authentication: Not Required - Confidentiality Impact: None - Integrity Impact: Partial - Availability Impact: None 影响后果: Gain Access 修复方案: As of September 1, 2014, no remedy available. 漏洞描述: An attacker could use this vulnerability to steal the victim’s cookie-based authentication credentials. 保护措施: - Cross_Site_Scripting (Nov 11, 2008) - HTTP_GETargscript (Feb 21, 2005) 受影响产品: YaBB YaBB 1 SP1.3.2 Gold 外部链接: - BID-11215 - CVE-2004-2402 - BugTraq Mailing List - YABB Web site