YaBB is prone to a weakness that may permit remote users to enumerate usernames. This could aid in further attacks.
It should be noted that this issue would only present a security risk on installations that do not allow guests or anonymous web users to browse the forum, in which case remote users would not be privy to usernames.
This issue was reported in YaBB 1 Gold - SP 1.3.1. Other versions may also be affected.
There is no exploit required.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: firstname.lastname@example.org <mailto:email@example.com>.