YaBB records
29 published records for vendor yabb.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 8
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
29 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
42Plan | CVE-2007-3208No exploit | CRLF injection vulnerability in Yet another Bulletin Board (YaBB) 2.1 allows remote attackers to obtain administrative access via requests tyabb · yabb | Critical10.0 | — | 5.9% | Jun 14, 2007 |
41Plan | CVE-2004-2403No exploit | Cross-site request forgery (CSRF) vulnerability in YaBB 1 GOLD SP 1.3.2 allows remote attackers to perform unauthorized actions as the adminyabb · yabb | Critical10.0 | — | 2.8% | Dec 31, 2004 |
41Plan | CVE-2004-0343Proof of concept | Multiple SQL injection vulnerabilities in YaBB SE 1.5.4 through 1.5.5b allow remote attackers to execute arbitrary SQL via (1) the msg paramyabb · yabb | Critical10.0 | — | 1.8% | Nov 23, 2004 |
40Plan | CVE-2013-2057No exploit | YaBB through 2.5.2: 'guestlanguage' Cookie Parameter Local File Include Vulnerabilityyabb · yabb · CWE-434 | Critical9.8 | — | 2.1% | Feb 11, 2020 |
33Monitor | CVE-2002-0955Proof of concept | Cross-site scripting vulnerability in YaBB.cgi for Yet Another Bulletin Board (YaBB) 1 Gold SP1 and earlier allows remote attackers to execuyabb · yabb | High7.5 | — | 8.6% | Oct 4, 2002 |
32Monitor | CVE-2000-1176Proof of concept | Directory traversal vulnerability in YaBB search.pl CGI script allows remote attackers to read arbitrary files via a ..yabb · yabb | High7.5 | — | 5.7% | Jan 9, 2001 |
31Monitor | CVE-2002-0117Proof of concept | Cross-site scripting vulnerability in Yet Another Bulletin Board (YaBB) 1 Gold SP 1 and earlier allows remote attackers to execute arbitraryyabb · yabb | High7.5 | — | 2.8% | Mar 25, 2002 |
31Monitor | CVE-2004-2754Proof of concept | SQL injection vulnerability in SSI.php in YaBB SE 1.5.4, 1.5.3, and possibly other versions before 1.5.5 allows remote attackers to execute yabb · yabb se · CWE-89 | High7.5 | — | 2.4% | Dec 31, 2004 |
31Monitor | CVE-2004-2139No exploit | Unknown vulnerability in Adminedit.pl YaBB 1 Gold before 1.3.2 allows attackers to execute arbitrary code via settings.pl.yabb · yabb | High7.5 | — | 2.1% | Dec 31, 2004 |
30Monitor | CVE-2006-3275No exploit | SQL injection vulnerability in profile.php in YaBB SE 1.5.5 and earlier allows remote attackers to execute SQL commands via a double-encodedyabb · yabb | High7.5 | — | 1.2% | Jun 28, 2006 |
28Monitor | CVE-2006-4157Proof of concept | Cross-site scripting (XSS) vulnerability in index.php in Yet another Bulletin Board (YaBB) allows remote attackers to inject arbitrary web syabb · yabb | Medium6.8 | — | 2.0% | Aug 16, 2006 |
26Monitor | CVE-2004-0344Proof of concept | Directory traversal vulnerability in ModifyMessage.php in YaBB SE 1.5.4 through 1.5.5b allows remote attackers to delete arbitrary files viayabb · yabb | Medium6.4 | — | 2.2% | Nov 23, 2004 |
26Monitor | CVE-2007-3295No exploit | Directory traversal vulnerability in Yet another Bulletin Board (YaBB) 2.1 and earlier allows remote authenticated users to execute arbitraryabb · yabb | Medium6.5 | — | 1.4% | Jun 20, 2007 |
22Monitor | CVE-2000-0853Proof of concept | YaBB Bulletin Board 9.1.2000 allows remote attackers to read arbitrary files via a ..yabb · yabb | Medium5.0 | — | 7.6% | Nov 14, 2000 |
20Monitor | CVE-2004-1662No exploit | YaBB SE 1.5.1 allows remote attackers to obtain sensitive information via a direct HTTP request to Admin.php, which reveals the full path inyabb · yabb | Medium5.0 | — | 1.6% | Aug 25, 2004 |
20Monitor | CVE-2004-1982No exploit | Post.pl in YaBB 1 Gold SP 1.2 allows remote attackers to modify records in the board's .txt file via carriage return characters in the subjeyabb · yabb | Medium5.0 | — | 1.5% | May 3, 2004 |
20Monitor | CVE-2004-0291Proof of concept | SQL injection vulnerability in post.php for YaBB SE 1.5.4 and 1.5.5 allows remote attackers to obtain hashed passwords via the quote parametyabb · yabb | Medium5.0 | — | 1.4% | Nov 23, 2004 |
20Monitor | CVE-2005-2296No exploit | YabbSE 1.5.5c allows remote attackers to obtain sensitive information via a direct request to ssi_examples.php, which reveals the path.yabb · yabb | Medium5.0 | — | 1.2% | Jul 18, 2005 |
20Monitor | CVE-2003-0275No exploit | SSI.php in YaBB SE 1.5.2 allows remote attackers to execute arbitrary PHP code by modifying the sourcedir parameter to reference a URL on a yabb · yabb | Medium5.1 | — | 1.1% | Jun 16, 2003 |
20Monitor | CVE-2002-1846No exploit | Yet Another Bulletin Board (YaBB) 1.40 and 1.41 does not require a user to submit the correct password before changing it to a new password,yabb · yabb | Medium5.0 | — | 1.1% | Dec 31, 2002 |
20Monitor | CVE-2004-2140No exploit | CRLF injection vulnerability in YaBB 1 Gold before 1.3.2 allows remote attackers to modify text file contents via the subject variable.yabb · yabb | Medium5.0 | — | 1.0% | Dec 31, 2004 |
18Monitor | CVE-2002-1845Proof of concept | Cross-site scripting (XSS) vulnerability in index.php in Yet Another Bulletin Board (YaBB) 1.40 and 1.41 allows remote attackers to inject ayabb · yabb | Medium4.3 | — | 3.9% | Dec 31, 2002 |
18Monitor | CVE-2004-1827Proof of concept | Cross-site scripting (XSS) vulnerability in YaBB 1 Gold(SP1.3) and YaBB SE 1.5.1 Final allows remote attackers to inject arbitrary web scripyabb · yabb | Medium4.3 | — | 2.1% | Mar 15, 2004 |
17Monitor | CVE-2002-2296Proof of concept | Cross-site scripting (XSS) vulnerability in YaBB.pl in Yet Another Bulletin Board (YaBB) 1 Gold SP 1 allows remote attackers to inject arbityabb · yabb · CWE-79 | Medium4.3 | — | 1.4% | Dec 31, 2002 |
17Monitor | CVE-2005-0741Proof of concept | Cross-site scripting (XSS) vulnerability in YaBB.pl for YaBB 2.0 RC1 allows remote attackers to inject arbitrary web script or HTML via the yabb · yabb | Medium4.3 | — | 1.4% | Mar 8, 2005 |
- CVE-2007-320842Plan
CRLF injection vulnerability in Yet another Bulletin Board (YaBB) 2.1 allows remote attackers to obtain administrative access via requests t
CriticalCVSS 10.0No exploitEPSS 6%yabb · yabbJun 14, 2007
- CVE-2004-240341Plan
Cross-site request forgery (CSRF) vulnerability in YaBB 1 GOLD SP 1.3.2 allows remote attackers to perform unauthorized actions as the admin
CriticalCVSS 10.0No exploitEPSS 3%yabb · yabbDec 31, 2004
- CVE-2004-034341Plan
Multiple SQL injection vulnerabilities in YaBB SE 1.5.4 through 1.5.5b allow remote attackers to execute arbitrary SQL via (1) the msg param
CriticalCVSS 10.0Proof of conceptEPSS 2%yabb · yabbNov 23, 2004
- CVE-2013-205740Plan
YaBB through 2.5.2: 'guestlanguage' Cookie Parameter Local File Include Vulnerability
CriticalCVSS 9.8No exploitEPSS 2%yabb · yabbFeb 11, 2020
- CVE-2002-095533Monitor
Cross-site scripting vulnerability in YaBB.cgi for Yet Another Bulletin Board (YaBB) 1 Gold SP1 and earlier allows remote attackers to execu
HighCVSS 7.5Proof of conceptEPSS 9%yabb · yabbOct 4, 2002
- CVE-2000-117632Monitor
Directory traversal vulnerability in YaBB search.pl CGI script allows remote attackers to read arbitrary files via a ..
HighCVSS 7.5Proof of conceptEPSS 6%yabb · yabbJan 9, 2001
- CVE-2002-011731Monitor
Cross-site scripting vulnerability in Yet Another Bulletin Board (YaBB) 1 Gold SP 1 and earlier allows remote attackers to execute arbitrary
HighCVSS 7.5Proof of conceptEPSS 3%yabb · yabbMar 25, 2002
- CVE-2004-275431Monitor
SQL injection vulnerability in SSI.php in YaBB SE 1.5.4, 1.5.3, and possibly other versions before 1.5.5 allows remote attackers to execute
HighCVSS 7.5Proof of conceptEPSS 2%yabb · yabb seDec 31, 2004
- CVE-2004-213931Monitor
Unknown vulnerability in Adminedit.pl YaBB 1 Gold before 1.3.2 allows attackers to execute arbitrary code via settings.pl.
HighCVSS 7.5No exploitEPSS 2%yabb · yabbDec 31, 2004
- CVE-2006-327530Monitor
SQL injection vulnerability in profile.php in YaBB SE 1.5.5 and earlier allows remote attackers to execute SQL commands via a double-encoded
HighCVSS 7.5No exploitEPSS 1%yabb · yabbJun 28, 2006
- CVE-2006-415728Monitor
Cross-site scripting (XSS) vulnerability in index.php in Yet another Bulletin Board (YaBB) allows remote attackers to inject arbitrary web s
MediumCVSS 6.8Proof of conceptEPSS 2%yabb · yabbAug 16, 2006
- CVE-2004-034426Monitor
Directory traversal vulnerability in ModifyMessage.php in YaBB SE 1.5.4 through 1.5.5b allows remote attackers to delete arbitrary files via
MediumCVSS 6.4Proof of conceptEPSS 2%yabb · yabbNov 23, 2004
- CVE-2007-329526Monitor
Directory traversal vulnerability in Yet another Bulletin Board (YaBB) 2.1 and earlier allows remote authenticated users to execute arbitrar
MediumCVSS 6.5No exploitEPSS 1%yabb · yabbJun 20, 2007
- CVE-2000-085322Monitor
YaBB Bulletin Board 9.1.2000 allows remote attackers to read arbitrary files via a ..
MediumCVSS 5.0Proof of conceptEPSS 8%yabb · yabbNov 14, 2000
- CVE-2004-166220Monitor
YaBB SE 1.5.1 allows remote attackers to obtain sensitive information via a direct HTTP request to Admin.php, which reveals the full path in
MediumCVSS 5.0No exploitEPSS 2%yabb · yabbAug 25, 2004
- CVE-2004-198220Monitor
Post.pl in YaBB 1 Gold SP 1.2 allows remote attackers to modify records in the board's .txt file via carriage return characters in the subje
MediumCVSS 5.0No exploitEPSS 1%yabb · yabbMay 3, 2004
- CVE-2004-029120Monitor
SQL injection vulnerability in post.php for YaBB SE 1.5.4 and 1.5.5 allows remote attackers to obtain hashed passwords via the quote paramet
MediumCVSS 5.0Proof of conceptEPSS 1%yabb · yabbNov 23, 2004
- CVE-2005-229620Monitor
YabbSE 1.5.5c allows remote attackers to obtain sensitive information via a direct request to ssi_examples.php, which reveals the path.
MediumCVSS 5.0No exploitEPSS 1%yabb · yabbJul 18, 2005
- CVE-2003-027520Monitor
SSI.php in YaBB SE 1.5.2 allows remote attackers to execute arbitrary PHP code by modifying the sourcedir parameter to reference a URL on a
MediumCVSS 5.1No exploitEPSS 1%yabb · yabbJun 16, 2003
- CVE-2002-184620Monitor
Yet Another Bulletin Board (YaBB) 1.40 and 1.41 does not require a user to submit the correct password before changing it to a new password,
MediumCVSS 5.0No exploitEPSS 1%yabb · yabbDec 31, 2002
- CVE-2004-214020Monitor
CRLF injection vulnerability in YaBB 1 Gold before 1.3.2 allows remote attackers to modify text file contents via the subject variable.
MediumCVSS 5.0No exploitEPSS 1%yabb · yabbDec 31, 2004
- CVE-2002-184518Monitor
Cross-site scripting (XSS) vulnerability in index.php in Yet Another Bulletin Board (YaBB) 1.40 and 1.41 allows remote attackers to inject a
MediumCVSS 4.3Proof of conceptEPSS 4%yabb · yabbDec 31, 2002
- CVE-2004-182718Monitor
Cross-site scripting (XSS) vulnerability in YaBB 1 Gold(SP1.3) and YaBB SE 1.5.1 Final allows remote attackers to inject arbitrary web scrip
MediumCVSS 4.3Proof of conceptEPSS 2%yabb · yabbMar 15, 2004
- CVE-2002-229617Monitor
Cross-site scripting (XSS) vulnerability in YaBB.pl in Yet Another Bulletin Board (YaBB) 1 Gold SP 1 allows remote attackers to inject arbit
MediumCVSS 4.3Proof of conceptEPSS 1%yabb · yabbDec 31, 2002
- CVE-2005-074117Monitor
Cross-site scripting (XSS) vulnerability in YaBB.pl for YaBB 2.0 RC1 allows remote attackers to inject arbitrary web script or HTML via the
MediumCVSS 4.3Proof of conceptEPSS 1%yabb · yabbMar 8, 2005