10

CVE-2004-0343

Exploit

Multiple SQL injection vulnerabilities in YaBB SE 1.5.4 through 1.5.5b allow remote attackers to execute arbitrary SQL via (1) the msg parameter in ModifyMessage.php or (2) the postid parameter in ModifyMessage.php.

Data is provided by the National Vulnerability Database (NVD)
YabbYabb Version1.5.4 Editionsecond_edition
YabbYabb Version1.5.5 Editionsecond_edition
YabbYabb Version1.5.5b Editionsecond_edition
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.32% 0.515
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C