5
CVSSv2

CVE-2004-0291

Published: 23/11/2004 Updated: 11/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

SQL injection vulnerability in post.php for YaBB SE 1.5.4 and 1.5.5 allows remote malicious users to obtain hashed passwords via the quote parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

yabb yabb 1.5.4

yabb yabb 1.5.5

Exploits

source: wwwsecurityfocuscom/bid/9674/info It has been reported that YaBB SE may be prone to a SQL injection vulnerability that may allow a remote user to inject arbitrary SQL queries into the database used by the software YaBB SE versions 154 and 155 have been reported to be affected by this issue, however, other versions could be ...