10
CVSSv2

CVE-2004-0343

Published: 23/11/2004 Updated: 11/07/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Multiple SQL injection vulnerabilities in YaBB SE 1.5.4 up to and including 1.5.5b allow remote malicious users to execute arbitrary SQL via (1) the msg parameter in ModifyMessage.php or (2) the postid parameter in ModifyMessage.php.

Vulnerable Product Search on Vulmon Subscribe to Product

yabb yabb 1.5.4

yabb yabb 1.5.5

yabb yabb 1.5.5b

Exploits

source: wwwsecurityfocuscom/bid/9774/info It has been reported that YaBB SE may be prone to multiple vulnerabilities due to improper input validation The issues may allow an attacker to carry out SQL injection and directory traversal attacks Successful exploitation of these issues may allow an attacker to gain access to sensitive infor ...