YaBB kayıtları
yabb üreticisine ait 29 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 8
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
29 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
42Planlayın | CVE-2007-3208İstismar yok | CRLF injection vulnerability in Yet another Bulletin Board (YaBB) 2.1 allows remote attackers to obtain administrative access via requests tyabb · yabb | Kritik10,0 | — | %5,9 | 14 Haz 2007 |
41Planlayın | CVE-2004-2403İstismar yok | Cross-site request forgery (CSRF) vulnerability in YaBB 1 GOLD SP 1.3.2 allows remote attackers to perform unauthorized actions as the adminyabb · yabb | Kritik10,0 | — | %2,8 | 31 Ara 2004 |
41Planlayın | CVE-2004-0343Kavram kanıtı | Multiple SQL injection vulnerabilities in YaBB SE 1.5.4 through 1.5.5b allow remote attackers to execute arbitrary SQL via (1) the msg paramyabb · yabb | Kritik10,0 | — | %1,8 | 23 Kas 2004 |
40Planlayın | CVE-2013-2057İstismar yok | YaBB through 2.5.2: 'guestlanguage' Cookie Parameter Local File Include Vulnerabilityyabb · yabb · CWE-434 | Kritik9,8 | — | %2,1 | 11 Şub 2020 |
33İzleyin | CVE-2002-0955Kavram kanıtı | Cross-site scripting vulnerability in YaBB.cgi for Yet Another Bulletin Board (YaBB) 1 Gold SP1 and earlier allows remote attackers to execuyabb · yabb | Yüksek7,5 | — | %8,6 | 4 Eki 2002 |
32İzleyin | CVE-2000-1176Kavram kanıtı | Directory traversal vulnerability in YaBB search.pl CGI script allows remote attackers to read arbitrary files via a ..yabb · yabb | Yüksek7,5 | — | %5,7 | 9 Oca 2001 |
31İzleyin | CVE-2002-0117Kavram kanıtı | Cross-site scripting vulnerability in Yet Another Bulletin Board (YaBB) 1 Gold SP 1 and earlier allows remote attackers to execute arbitraryyabb · yabb | Yüksek7,5 | — | %2,8 | 25 Mar 2002 |
31İzleyin | CVE-2004-2754Kavram kanıtı | SQL injection vulnerability in SSI.php in YaBB SE 1.5.4, 1.5.3, and possibly other versions before 1.5.5 allows remote attackers to execute yabb · yabb se · CWE-89 | Yüksek7,5 | — | %2,4 | 31 Ara 2004 |
31İzleyin | CVE-2004-2139İstismar yok | Unknown vulnerability in Adminedit.pl YaBB 1 Gold before 1.3.2 allows attackers to execute arbitrary code via settings.pl.yabb · yabb | Yüksek7,5 | — | %2,1 | 31 Ara 2004 |
30İzleyin | CVE-2006-3275İstismar yok | SQL injection vulnerability in profile.php in YaBB SE 1.5.5 and earlier allows remote attackers to execute SQL commands via a double-encodedyabb · yabb | Yüksek7,5 | — | %1,2 | 28 Haz 2006 |
28İzleyin | CVE-2006-4157Kavram kanıtı | Cross-site scripting (XSS) vulnerability in index.php in Yet another Bulletin Board (YaBB) allows remote attackers to inject arbitrary web syabb · yabb | Orta6,8 | — | %2,0 | 16 Ağu 2006 |
26İzleyin | CVE-2004-0344Kavram kanıtı | Directory traversal vulnerability in ModifyMessage.php in YaBB SE 1.5.4 through 1.5.5b allows remote attackers to delete arbitrary files viayabb · yabb | Orta6,4 | — | %2,2 | 23 Kas 2004 |
26İzleyin | CVE-2007-3295İstismar yok | Directory traversal vulnerability in Yet another Bulletin Board (YaBB) 2.1 and earlier allows remote authenticated users to execute arbitraryabb · yabb | Orta6,5 | — | %1,4 | 20 Haz 2007 |
22İzleyin | CVE-2000-0853Kavram kanıtı | YaBB Bulletin Board 9.1.2000 allows remote attackers to read arbitrary files via a ..yabb · yabb | Orta5,0 | — | %7,6 | 14 Kas 2000 |
20İzleyin | CVE-2004-1662İstismar yok | YaBB SE 1.5.1 allows remote attackers to obtain sensitive information via a direct HTTP request to Admin.php, which reveals the full path inyabb · yabb | Orta5,0 | — | %1,6 | 25 Ağu 2004 |
20İzleyin | CVE-2004-1982İstismar yok | Post.pl in YaBB 1 Gold SP 1.2 allows remote attackers to modify records in the board's .txt file via carriage return characters in the subjeyabb · yabb | Orta5,0 | — | %1,5 | 3 May 2004 |
20İzleyin | CVE-2004-0291Kavram kanıtı | SQL injection vulnerability in post.php for YaBB SE 1.5.4 and 1.5.5 allows remote attackers to obtain hashed passwords via the quote parametyabb · yabb | Orta5,0 | — | %1,4 | 23 Kas 2004 |
20İzleyin | CVE-2005-2296İstismar yok | YabbSE 1.5.5c allows remote attackers to obtain sensitive information via a direct request to ssi_examples.php, which reveals the path.yabb · yabb | Orta5,0 | — | %1,2 | 18 Tem 2005 |
20İzleyin | CVE-2003-0275İstismar yok | SSI.php in YaBB SE 1.5.2 allows remote attackers to execute arbitrary PHP code by modifying the sourcedir parameter to reference a URL on a yabb · yabb | Orta5,1 | — | %1,1 | 16 Haz 2003 |
20İzleyin | CVE-2002-1846İstismar yok | Yet Another Bulletin Board (YaBB) 1.40 and 1.41 does not require a user to submit the correct password before changing it to a new password,yabb · yabb | Orta5,0 | — | %1,1 | 31 Ara 2002 |
20İzleyin | CVE-2004-2140İstismar yok | CRLF injection vulnerability in YaBB 1 Gold before 1.3.2 allows remote attackers to modify text file contents via the subject variable.yabb · yabb | Orta5,0 | — | %1,0 | 31 Ara 2004 |
18İzleyin | CVE-2002-1845Kavram kanıtı | Cross-site scripting (XSS) vulnerability in index.php in Yet Another Bulletin Board (YaBB) 1.40 and 1.41 allows remote attackers to inject ayabb · yabb | Orta4,3 | — | %3,9 | 31 Ara 2002 |
18İzleyin | CVE-2004-1827Kavram kanıtı | Cross-site scripting (XSS) vulnerability in YaBB 1 Gold(SP1.3) and YaBB SE 1.5.1 Final allows remote attackers to inject arbitrary web scripyabb · yabb | Orta4,3 | — | %2,1 | 15 Mar 2004 |
17İzleyin | CVE-2002-2296Kavram kanıtı | Cross-site scripting (XSS) vulnerability in YaBB.pl in Yet Another Bulletin Board (YaBB) 1 Gold SP 1 allows remote attackers to inject arbityabb · yabb · CWE-79 | Orta4,3 | — | %1,4 | 31 Ara 2002 |
17İzleyin | CVE-2005-0741Kavram kanıtı | Cross-site scripting (XSS) vulnerability in YaBB.pl for YaBB 2.0 RC1 allows remote attackers to inject arbitrary web script or HTML via the yabb · yabb | Orta4,3 | — | %1,4 | 8 Mar 2005 |
- CVE-2007-320842Planlayın
CRLF injection vulnerability in Yet another Bulletin Board (YaBB) 2.1 allows remote attackers to obtain administrative access via requests t
KritikCVSS 10,0İstismar yokEPSS %6yabb · yabb14 Haz 2007
- CVE-2004-240341Planlayın
Cross-site request forgery (CSRF) vulnerability in YaBB 1 GOLD SP 1.3.2 allows remote attackers to perform unauthorized actions as the admin
KritikCVSS 10,0İstismar yokEPSS %3yabb · yabb31 Ara 2004
- CVE-2004-034341Planlayın
Multiple SQL injection vulnerabilities in YaBB SE 1.5.4 through 1.5.5b allow remote attackers to execute arbitrary SQL via (1) the msg param
KritikCVSS 10,0Kavram kanıtıEPSS %2yabb · yabb23 Kas 2004
- CVE-2013-205740Planlayın
YaBB through 2.5.2: 'guestlanguage' Cookie Parameter Local File Include Vulnerability
KritikCVSS 9,8İstismar yokEPSS %2yabb · yabb11 Şub 2020
- CVE-2002-095533İzleyin
Cross-site scripting vulnerability in YaBB.cgi for Yet Another Bulletin Board (YaBB) 1 Gold SP1 and earlier allows remote attackers to execu
YüksekCVSS 7,5Kavram kanıtıEPSS %9yabb · yabb4 Eki 2002
- CVE-2000-117632İzleyin
Directory traversal vulnerability in YaBB search.pl CGI script allows remote attackers to read arbitrary files via a ..
YüksekCVSS 7,5Kavram kanıtıEPSS %6yabb · yabb9 Oca 2001
- CVE-2002-011731İzleyin
Cross-site scripting vulnerability in Yet Another Bulletin Board (YaBB) 1 Gold SP 1 and earlier allows remote attackers to execute arbitrary
YüksekCVSS 7,5Kavram kanıtıEPSS %3yabb · yabb25 Mar 2002
- CVE-2004-275431İzleyin
SQL injection vulnerability in SSI.php in YaBB SE 1.5.4, 1.5.3, and possibly other versions before 1.5.5 allows remote attackers to execute
YüksekCVSS 7,5Kavram kanıtıEPSS %2yabb · yabb se31 Ara 2004
- CVE-2004-213931İzleyin
Unknown vulnerability in Adminedit.pl YaBB 1 Gold before 1.3.2 allows attackers to execute arbitrary code via settings.pl.
YüksekCVSS 7,5İstismar yokEPSS %2yabb · yabb31 Ara 2004
- CVE-2006-327530İzleyin
SQL injection vulnerability in profile.php in YaBB SE 1.5.5 and earlier allows remote attackers to execute SQL commands via a double-encoded
YüksekCVSS 7,5İstismar yokEPSS %1yabb · yabb28 Haz 2006
- CVE-2006-415728İzleyin
Cross-site scripting (XSS) vulnerability in index.php in Yet another Bulletin Board (YaBB) allows remote attackers to inject arbitrary web s
OrtaCVSS 6,8Kavram kanıtıEPSS %2yabb · yabb16 Ağu 2006
- CVE-2004-034426İzleyin
Directory traversal vulnerability in ModifyMessage.php in YaBB SE 1.5.4 through 1.5.5b allows remote attackers to delete arbitrary files via
OrtaCVSS 6,4Kavram kanıtıEPSS %2yabb · yabb23 Kas 2004
- CVE-2007-329526İzleyin
Directory traversal vulnerability in Yet another Bulletin Board (YaBB) 2.1 and earlier allows remote authenticated users to execute arbitrar
OrtaCVSS 6,5İstismar yokEPSS %1yabb · yabb20 Haz 2007
- CVE-2000-085322İzleyin
YaBB Bulletin Board 9.1.2000 allows remote attackers to read arbitrary files via a ..
OrtaCVSS 5,0Kavram kanıtıEPSS %8yabb · yabb14 Kas 2000
- CVE-2004-166220İzleyin
YaBB SE 1.5.1 allows remote attackers to obtain sensitive information via a direct HTTP request to Admin.php, which reveals the full path in
OrtaCVSS 5,0İstismar yokEPSS %2yabb · yabb25 Ağu 2004
- CVE-2004-198220İzleyin
Post.pl in YaBB 1 Gold SP 1.2 allows remote attackers to modify records in the board's .txt file via carriage return characters in the subje
OrtaCVSS 5,0İstismar yokEPSS %1yabb · yabb3 May 2004
- CVE-2004-029120İzleyin
SQL injection vulnerability in post.php for YaBB SE 1.5.4 and 1.5.5 allows remote attackers to obtain hashed passwords via the quote paramet
OrtaCVSS 5,0Kavram kanıtıEPSS %1yabb · yabb23 Kas 2004
- CVE-2005-229620İzleyin
YabbSE 1.5.5c allows remote attackers to obtain sensitive information via a direct request to ssi_examples.php, which reveals the path.
OrtaCVSS 5,0İstismar yokEPSS %1yabb · yabb18 Tem 2005
- CVE-2003-027520İzleyin
SSI.php in YaBB SE 1.5.2 allows remote attackers to execute arbitrary PHP code by modifying the sourcedir parameter to reference a URL on a
OrtaCVSS 5,1İstismar yokEPSS %1yabb · yabb16 Haz 2003
- CVE-2002-184620İzleyin
Yet Another Bulletin Board (YaBB) 1.40 and 1.41 does not require a user to submit the correct password before changing it to a new password,
OrtaCVSS 5,0İstismar yokEPSS %1yabb · yabb31 Ara 2002
- CVE-2004-214020İzleyin
CRLF injection vulnerability in YaBB 1 Gold before 1.3.2 allows remote attackers to modify text file contents via the subject variable.
OrtaCVSS 5,0İstismar yokEPSS %1yabb · yabb31 Ara 2004
- CVE-2002-184518İzleyin
Cross-site scripting (XSS) vulnerability in index.php in Yet Another Bulletin Board (YaBB) 1.40 and 1.41 allows remote attackers to inject a
OrtaCVSS 4,3Kavram kanıtıEPSS %4yabb · yabb31 Ara 2002
- CVE-2004-182718İzleyin
Cross-site scripting (XSS) vulnerability in YaBB 1 Gold(SP1.3) and YaBB SE 1.5.1 Final allows remote attackers to inject arbitrary web scrip
OrtaCVSS 4,3Kavram kanıtıEPSS %2yabb · yabb15 Mar 2004
- CVE-2002-229617İzleyin
Cross-site scripting (XSS) vulnerability in YaBB.pl in Yet Another Bulletin Board (YaBB) 1 Gold SP 1 allows remote attackers to inject arbit
OrtaCVSS 4,3Kavram kanıtıEPSS %1yabb · yabb31 Ara 2002
- CVE-2005-074117İzleyin
Cross-site scripting (XSS) vulnerability in YaBB.pl for YaBB 2.0 RC1 allows remote attackers to inject arbitrary web script or HTML via the
OrtaCVSS 4,3Kavram kanıtıEPSS %1yabb · yabb8 Mar 2005