Перейти к содержимому
Noroxi

Записи YaBB

29 опубликованных записей вендора yabb.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
8
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Записи по годам

  1. 20

Столбик: всего · тёмная часть: CISA KEV.

Повторяющиеся классы

Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.

CWE

Все записи

29 записей
  • CVE-2007-3208
    42В плане

    CRLF injection vulnerability in Yet another Bulletin Board (YaBB) 2.1 allows remote attackers to obtain administrative access via requests t

    КритическаяCVSS 10,0Эксплойта нетEPSS 6 %

    yabb · yabb14 июн. 2007 г.

  • CVE-2004-2403
    41В плане

    Cross-site request forgery (CSRF) vulnerability in YaBB 1 GOLD SP 1.3.2 allows remote attackers to perform unauthorized actions as the admin

    КритическаяCVSS 10,0Эксплойта нетEPSS 3 %

    yabb · yabb31 дек. 2004 г.

  • CVE-2004-0343
    41В плане

    Multiple SQL injection vulnerabilities in YaBB SE 1.5.4 through 1.5.5b allow remote attackers to execute arbitrary SQL via (1) the msg param

    КритическаяCVSS 10,0Proof of conceptEPSS 2 %

    yabb · yabb23 нояб. 2004 г.

  • CVE-2013-2057
    40В плане

    YaBB through 2.5.2: 'guestlanguage' Cookie Parameter Local File Include Vulnerability

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    yabb · yabb11 февр. 2020 г.

  • CVE-2002-0955
    33Наблюдать

    Cross-site scripting vulnerability in YaBB.cgi for Yet Another Bulletin Board (YaBB) 1 Gold SP1 and earlier allows remote attackers to execu

    ВысокаяCVSS 7,5Proof of conceptEPSS 9 %

    yabb · yabb4 окт. 2002 г.

  • CVE-2000-1176
    32Наблюдать

    Directory traversal vulnerability in YaBB search.pl CGI script allows remote attackers to read arbitrary files via a ..

    ВысокаяCVSS 7,5Proof of conceptEPSS 6 %

    yabb · yabb9 янв. 2001 г.

  • CVE-2002-0117
    31Наблюдать

    Cross-site scripting vulnerability in Yet Another Bulletin Board (YaBB) 1 Gold SP 1 and earlier allows remote attackers to execute arbitrary

    ВысокаяCVSS 7,5Proof of conceptEPSS 3 %

    yabb · yabb25 мар. 2002 г.

  • CVE-2004-2754
    31Наблюдать

    SQL injection vulnerability in SSI.php in YaBB SE 1.5.4, 1.5.3, and possibly other versions before 1.5.5 allows remote attackers to execute

    ВысокаяCVSS 7,5Proof of conceptEPSS 2 %

    yabb · yabb se31 дек. 2004 г.

  • CVE-2004-2139
    31Наблюдать

    Unknown vulnerability in Adminedit.pl YaBB 1 Gold before 1.3.2 allows attackers to execute arbitrary code via settings.pl.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    yabb · yabb31 дек. 2004 г.

  • CVE-2006-3275
    30Наблюдать

    SQL injection vulnerability in profile.php in YaBB SE 1.5.5 and earlier allows remote attackers to execute SQL commands via a double-encoded

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    yabb · yabb28 июн. 2006 г.

  • CVE-2006-4157
    28Наблюдать

    Cross-site scripting (XSS) vulnerability in index.php in Yet another Bulletin Board (YaBB) allows remote attackers to inject arbitrary web s

    СредняяCVSS 6,8Proof of conceptEPSS 2 %

    yabb · yabb16 авг. 2006 г.

  • CVE-2004-0344
    26Наблюдать

    Directory traversal vulnerability in ModifyMessage.php in YaBB SE 1.5.4 through 1.5.5b allows remote attackers to delete arbitrary files via

    СредняяCVSS 6,4Proof of conceptEPSS 2 %

    yabb · yabb23 нояб. 2004 г.

  • CVE-2007-3295
    26Наблюдать

    Directory traversal vulnerability in Yet another Bulletin Board (YaBB) 2.1 and earlier allows remote authenticated users to execute arbitrar

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    yabb · yabb20 июн. 2007 г.

  • CVE-2000-0853
    22Наблюдать

    YaBB Bulletin Board 9.1.2000 allows remote attackers to read arbitrary files via a ..

    СредняяCVSS 5,0Proof of conceptEPSS 8 %

    yabb · yabb14 нояб. 2000 г.

  • CVE-2004-1662
    20Наблюдать

    YaBB SE 1.5.1 allows remote attackers to obtain sensitive information via a direct HTTP request to Admin.php, which reveals the full path in

    СредняяCVSS 5,0Эксплойта нетEPSS 2 %

    yabb · yabb25 авг. 2004 г.

  • CVE-2004-1982
    20Наблюдать

    Post.pl in YaBB 1 Gold SP 1.2 allows remote attackers to modify records in the board's .txt file via carriage return characters in the subje

    СредняяCVSS 5,0Эксплойта нетEPSS 1 %

    yabb · yabb3 мая 2004 г.

  • CVE-2004-0291
    20Наблюдать

    SQL injection vulnerability in post.php for YaBB SE 1.5.4 and 1.5.5 allows remote attackers to obtain hashed passwords via the quote paramet

    СредняяCVSS 5,0Proof of conceptEPSS 1 %

    yabb · yabb23 нояб. 2004 г.

  • CVE-2005-2296
    20Наблюдать

    YabbSE 1.5.5c allows remote attackers to obtain sensitive information via a direct request to ssi_examples.php, which reveals the path.

    СредняяCVSS 5,0Эксплойта нетEPSS 1 %

    yabb · yabb18 июл. 2005 г.

  • CVE-2003-0275
    20Наблюдать

    SSI.php in YaBB SE 1.5.2 allows remote attackers to execute arbitrary PHP code by modifying the sourcedir parameter to reference a URL on a

    СредняяCVSS 5,1Эксплойта нетEPSS 1 %

    yabb · yabb16 июн. 2003 г.

  • CVE-2002-1846
    20Наблюдать

    Yet Another Bulletin Board (YaBB) 1.40 and 1.41 does not require a user to submit the correct password before changing it to a new password,

    СредняяCVSS 5,0Эксплойта нетEPSS 1 %

    yabb · yabb31 дек. 2002 г.

  • CVE-2004-2140
    20Наблюдать

    CRLF injection vulnerability in YaBB 1 Gold before 1.3.2 allows remote attackers to modify text file contents via the subject variable.

    СредняяCVSS 5,0Эксплойта нетEPSS 1 %

    yabb · yabb31 дек. 2004 г.

  • CVE-2002-1845
    18Наблюдать

    Cross-site scripting (XSS) vulnerability in index.php in Yet Another Bulletin Board (YaBB) 1.40 and 1.41 allows remote attackers to inject a

    СредняяCVSS 4,3Proof of conceptEPSS 4 %

    yabb · yabb31 дек. 2002 г.

  • CVE-2004-1827
    18Наблюдать

    Cross-site scripting (XSS) vulnerability in YaBB 1 Gold(SP1.3) and YaBB SE 1.5.1 Final allows remote attackers to inject arbitrary web scrip

    СредняяCVSS 4,3Proof of conceptEPSS 2 %

    yabb · yabb15 мар. 2004 г.

  • CVE-2002-2296
    17Наблюдать

    Cross-site scripting (XSS) vulnerability in YaBB.pl in Yet Another Bulletin Board (YaBB) 1 Gold SP 1 allows remote attackers to inject arbit

    СредняяCVSS 4,3Proof of conceptEPSS 1 %

    yabb · yabb31 дек. 2002 г.

  • CVE-2005-0741
    17Наблюдать

    Cross-site scripting (XSS) vulnerability in YaBB.pl for YaBB 2.0 RC1 allows remote attackers to inject arbitrary web script or HTML via the

    СредняяCVSS 4,3Proof of conceptEPSS 1 %

    yabb · yabb8 мар. 2005 г.