Записи YaBB
29 опубликованных записей вендора yabb.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 8
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
29 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
42В плане | CVE-2007-3208Эксплойта нет | CRLF injection vulnerability in Yet another Bulletin Board (YaBB) 2.1 allows remote attackers to obtain administrative access via requests tyabb · yabb | Критическая10,0 | — | 5,9 % | 14 июн. 2007 г. |
41В плане | CVE-2004-2403Эксплойта нет | Cross-site request forgery (CSRF) vulnerability in YaBB 1 GOLD SP 1.3.2 allows remote attackers to perform unauthorized actions as the adminyabb · yabb | Критическая10,0 | — | 2,8 % | 31 дек. 2004 г. |
41В плане | CVE-2004-0343Proof of concept | Multiple SQL injection vulnerabilities in YaBB SE 1.5.4 through 1.5.5b allow remote attackers to execute arbitrary SQL via (1) the msg paramyabb · yabb | Критическая10,0 | — | 1,8 % | 23 нояб. 2004 г. |
40В плане | CVE-2013-2057Эксплойта нет | YaBB through 2.5.2: 'guestlanguage' Cookie Parameter Local File Include Vulnerabilityyabb · yabb · CWE-434 | Критическая9,8 | — | 2,1 % | 11 февр. 2020 г. |
33Наблюдать | CVE-2002-0955Proof of concept | Cross-site scripting vulnerability in YaBB.cgi for Yet Another Bulletin Board (YaBB) 1 Gold SP1 and earlier allows remote attackers to execuyabb · yabb | Высокая7,5 | — | 8,6 % | 4 окт. 2002 г. |
32Наблюдать | CVE-2000-1176Proof of concept | Directory traversal vulnerability in YaBB search.pl CGI script allows remote attackers to read arbitrary files via a ..yabb · yabb | Высокая7,5 | — | 5,7 % | 9 янв. 2001 г. |
31Наблюдать | CVE-2002-0117Proof of concept | Cross-site scripting vulnerability in Yet Another Bulletin Board (YaBB) 1 Gold SP 1 and earlier allows remote attackers to execute arbitraryyabb · yabb | Высокая7,5 | — | 2,8 % | 25 мар. 2002 г. |
31Наблюдать | CVE-2004-2754Proof of concept | SQL injection vulnerability in SSI.php in YaBB SE 1.5.4, 1.5.3, and possibly other versions before 1.5.5 allows remote attackers to execute yabb · yabb se · CWE-89 | Высокая7,5 | — | 2,4 % | 31 дек. 2004 г. |
31Наблюдать | CVE-2004-2139Эксплойта нет | Unknown vulnerability in Adminedit.pl YaBB 1 Gold before 1.3.2 allows attackers to execute arbitrary code via settings.pl.yabb · yabb | Высокая7,5 | — | 2,1 % | 31 дек. 2004 г. |
30Наблюдать | CVE-2006-3275Эксплойта нет | SQL injection vulnerability in profile.php in YaBB SE 1.5.5 and earlier allows remote attackers to execute SQL commands via a double-encodedyabb · yabb | Высокая7,5 | — | 1,2 % | 28 июн. 2006 г. |
28Наблюдать | CVE-2006-4157Proof of concept | Cross-site scripting (XSS) vulnerability in index.php in Yet another Bulletin Board (YaBB) allows remote attackers to inject arbitrary web syabb · yabb | Средняя6,8 | — | 2,0 % | 16 авг. 2006 г. |
26Наблюдать | CVE-2004-0344Proof of concept | Directory traversal vulnerability in ModifyMessage.php in YaBB SE 1.5.4 through 1.5.5b allows remote attackers to delete arbitrary files viayabb · yabb | Средняя6,4 | — | 2,2 % | 23 нояб. 2004 г. |
26Наблюдать | CVE-2007-3295Эксплойта нет | Directory traversal vulnerability in Yet another Bulletin Board (YaBB) 2.1 and earlier allows remote authenticated users to execute arbitraryabb · yabb | Средняя6,5 | — | 1,4 % | 20 июн. 2007 г. |
22Наблюдать | CVE-2000-0853Proof of concept | YaBB Bulletin Board 9.1.2000 allows remote attackers to read arbitrary files via a ..yabb · yabb | Средняя5,0 | — | 7,6 % | 14 нояб. 2000 г. |
20Наблюдать | CVE-2004-1662Эксплойта нет | YaBB SE 1.5.1 allows remote attackers to obtain sensitive information via a direct HTTP request to Admin.php, which reveals the full path inyabb · yabb | Средняя5,0 | — | 1,6 % | 25 авг. 2004 г. |
20Наблюдать | CVE-2004-1982Эксплойта нет | Post.pl in YaBB 1 Gold SP 1.2 allows remote attackers to modify records in the board's .txt file via carriage return characters in the subjeyabb · yabb | Средняя5,0 | — | 1,5 % | 3 мая 2004 г. |
20Наблюдать | CVE-2004-0291Proof of concept | SQL injection vulnerability in post.php for YaBB SE 1.5.4 and 1.5.5 allows remote attackers to obtain hashed passwords via the quote parametyabb · yabb | Средняя5,0 | — | 1,4 % | 23 нояб. 2004 г. |
20Наблюдать | CVE-2005-2296Эксплойта нет | YabbSE 1.5.5c allows remote attackers to obtain sensitive information via a direct request to ssi_examples.php, which reveals the path.yabb · yabb | Средняя5,0 | — | 1,2 % | 18 июл. 2005 г. |
20Наблюдать | CVE-2003-0275Эксплойта нет | SSI.php in YaBB SE 1.5.2 allows remote attackers to execute arbitrary PHP code by modifying the sourcedir parameter to reference a URL on a yabb · yabb | Средняя5,1 | — | 1,1 % | 16 июн. 2003 г. |
20Наблюдать | CVE-2002-1846Эксплойта нет | Yet Another Bulletin Board (YaBB) 1.40 and 1.41 does not require a user to submit the correct password before changing it to a new password,yabb · yabb | Средняя5,0 | — | 1,1 % | 31 дек. 2002 г. |
20Наблюдать | CVE-2004-2140Эксплойта нет | CRLF injection vulnerability in YaBB 1 Gold before 1.3.2 allows remote attackers to modify text file contents via the subject variable.yabb · yabb | Средняя5,0 | — | 1,0 % | 31 дек. 2004 г. |
18Наблюдать | CVE-2002-1845Proof of concept | Cross-site scripting (XSS) vulnerability in index.php in Yet Another Bulletin Board (YaBB) 1.40 and 1.41 allows remote attackers to inject ayabb · yabb | Средняя4,3 | — | 3,9 % | 31 дек. 2002 г. |
18Наблюдать | CVE-2004-1827Proof of concept | Cross-site scripting (XSS) vulnerability in YaBB 1 Gold(SP1.3) and YaBB SE 1.5.1 Final allows remote attackers to inject arbitrary web scripyabb · yabb | Средняя4,3 | — | 2,1 % | 15 мар. 2004 г. |
17Наблюдать | CVE-2002-2296Proof of concept | Cross-site scripting (XSS) vulnerability in YaBB.pl in Yet Another Bulletin Board (YaBB) 1 Gold SP 1 allows remote attackers to inject arbityabb · yabb · CWE-79 | Средняя4,3 | — | 1,4 % | 31 дек. 2002 г. |
17Наблюдать | CVE-2005-0741Proof of concept | Cross-site scripting (XSS) vulnerability in YaBB.pl for YaBB 2.0 RC1 allows remote attackers to inject arbitrary web script or HTML via the yabb · yabb | Средняя4,3 | — | 1,4 % | 8 мар. 2005 г. |
- CVE-2007-320842В плане
CRLF injection vulnerability in Yet another Bulletin Board (YaBB) 2.1 allows remote attackers to obtain administrative access via requests t
КритическаяCVSS 10,0Эксплойта нетEPSS 6 %yabb · yabb14 июн. 2007 г.
- CVE-2004-240341В плане
Cross-site request forgery (CSRF) vulnerability in YaBB 1 GOLD SP 1.3.2 allows remote attackers to perform unauthorized actions as the admin
КритическаяCVSS 10,0Эксплойта нетEPSS 3 %yabb · yabb31 дек. 2004 г.
- CVE-2004-034341В плане
Multiple SQL injection vulnerabilities in YaBB SE 1.5.4 through 1.5.5b allow remote attackers to execute arbitrary SQL via (1) the msg param
КритическаяCVSS 10,0Proof of conceptEPSS 2 %yabb · yabb23 нояб. 2004 г.
- CVE-2013-205740В плане
YaBB through 2.5.2: 'guestlanguage' Cookie Parameter Local File Include Vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %yabb · yabb11 февр. 2020 г.
- CVE-2002-095533Наблюдать
Cross-site scripting vulnerability in YaBB.cgi for Yet Another Bulletin Board (YaBB) 1 Gold SP1 and earlier allows remote attackers to execu
ВысокаяCVSS 7,5Proof of conceptEPSS 9 %yabb · yabb4 окт. 2002 г.
- CVE-2000-117632Наблюдать
Directory traversal vulnerability in YaBB search.pl CGI script allows remote attackers to read arbitrary files via a ..
ВысокаяCVSS 7,5Proof of conceptEPSS 6 %yabb · yabb9 янв. 2001 г.
- CVE-2002-011731Наблюдать
Cross-site scripting vulnerability in Yet Another Bulletin Board (YaBB) 1 Gold SP 1 and earlier allows remote attackers to execute arbitrary
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %yabb · yabb25 мар. 2002 г.
- CVE-2004-275431Наблюдать
SQL injection vulnerability in SSI.php in YaBB SE 1.5.4, 1.5.3, and possibly other versions before 1.5.5 allows remote attackers to execute
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %yabb · yabb se31 дек. 2004 г.
- CVE-2004-213931Наблюдать
Unknown vulnerability in Adminedit.pl YaBB 1 Gold before 1.3.2 allows attackers to execute arbitrary code via settings.pl.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %yabb · yabb31 дек. 2004 г.
- CVE-2006-327530Наблюдать
SQL injection vulnerability in profile.php in YaBB SE 1.5.5 and earlier allows remote attackers to execute SQL commands via a double-encoded
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %yabb · yabb28 июн. 2006 г.
- CVE-2006-415728Наблюдать
Cross-site scripting (XSS) vulnerability in index.php in Yet another Bulletin Board (YaBB) allows remote attackers to inject arbitrary web s
СредняяCVSS 6,8Proof of conceptEPSS 2 %yabb · yabb16 авг. 2006 г.
- CVE-2004-034426Наблюдать
Directory traversal vulnerability in ModifyMessage.php in YaBB SE 1.5.4 through 1.5.5b allows remote attackers to delete arbitrary files via
СредняяCVSS 6,4Proof of conceptEPSS 2 %yabb · yabb23 нояб. 2004 г.
- CVE-2007-329526Наблюдать
Directory traversal vulnerability in Yet another Bulletin Board (YaBB) 2.1 and earlier allows remote authenticated users to execute arbitrar
СредняяCVSS 6,5Эксплойта нетEPSS 1 %yabb · yabb20 июн. 2007 г.
- CVE-2000-085322Наблюдать
YaBB Bulletin Board 9.1.2000 allows remote attackers to read arbitrary files via a ..
СредняяCVSS 5,0Proof of conceptEPSS 8 %yabb · yabb14 нояб. 2000 г.
- CVE-2004-166220Наблюдать
YaBB SE 1.5.1 allows remote attackers to obtain sensitive information via a direct HTTP request to Admin.php, which reveals the full path in
СредняяCVSS 5,0Эксплойта нетEPSS 2 %yabb · yabb25 авг. 2004 г.
- CVE-2004-198220Наблюдать
Post.pl in YaBB 1 Gold SP 1.2 allows remote attackers to modify records in the board's .txt file via carriage return characters in the subje
СредняяCVSS 5,0Эксплойта нетEPSS 1 %yabb · yabb3 мая 2004 г.
- CVE-2004-029120Наблюдать
SQL injection vulnerability in post.php for YaBB SE 1.5.4 and 1.5.5 allows remote attackers to obtain hashed passwords via the quote paramet
СредняяCVSS 5,0Proof of conceptEPSS 1 %yabb · yabb23 нояб. 2004 г.
- CVE-2005-229620Наблюдать
YabbSE 1.5.5c allows remote attackers to obtain sensitive information via a direct request to ssi_examples.php, which reveals the path.
СредняяCVSS 5,0Эксплойта нетEPSS 1 %yabb · yabb18 июл. 2005 г.
- CVE-2003-027520Наблюдать
SSI.php in YaBB SE 1.5.2 allows remote attackers to execute arbitrary PHP code by modifying the sourcedir parameter to reference a URL on a
СредняяCVSS 5,1Эксплойта нетEPSS 1 %yabb · yabb16 июн. 2003 г.
- CVE-2002-184620Наблюдать
Yet Another Bulletin Board (YaBB) 1.40 and 1.41 does not require a user to submit the correct password before changing it to a new password,
СредняяCVSS 5,0Эксплойта нетEPSS 1 %yabb · yabb31 дек. 2002 г.
- CVE-2004-214020Наблюдать
CRLF injection vulnerability in YaBB 1 Gold before 1.3.2 allows remote attackers to modify text file contents via the subject variable.
СредняяCVSS 5,0Эксплойта нетEPSS 1 %yabb · yabb31 дек. 2004 г.
- CVE-2002-184518Наблюдать
Cross-site scripting (XSS) vulnerability in index.php in Yet Another Bulletin Board (YaBB) 1.40 and 1.41 allows remote attackers to inject a
СредняяCVSS 4,3Proof of conceptEPSS 4 %yabb · yabb31 дек. 2002 г.
- CVE-2004-182718Наблюдать
Cross-site scripting (XSS) vulnerability in YaBB 1 Gold(SP1.3) and YaBB SE 1.5.1 Final allows remote attackers to inject arbitrary web scrip
СредняяCVSS 4,3Proof of conceptEPSS 2 %yabb · yabb15 мар. 2004 г.
- CVE-2002-229617Наблюдать
Cross-site scripting (XSS) vulnerability in YaBB.pl in Yet Another Bulletin Board (YaBB) 1 Gold SP 1 allows remote attackers to inject arbit
СредняяCVSS 4,3Proof of conceptEPSS 1 %yabb · yabb31 дек. 2002 г.
- CVE-2005-074117Наблюдать
Cross-site scripting (XSS) vulnerability in YaBB.pl for YaBB 2.0 RC1 allows remote attackers to inject arbitrary web script or HTML via the
СредняяCVSS 4,3Proof of conceptEPSS 1 %yabb · yabb8 мар. 2005 г.