10
CVE-2007-3208
- EPSS 5.86%
- Veröffentlicht 14.06.2007 19:30:00
- Zuletzt bearbeitet 16.06.2026 22:41:16
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
CRLF injection vulnerability in Yet another Bulletin Board (YaBB) 2.1 allows remote attackers to obtain administrative access via requests to (1) register.pl or (2) profile.pl that write CRLF sequences to a .vars file. NOTE: this can be leveraged to execute arbitrary code.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 5.86% | 0.922 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 10 | 10 | 10 |
AV:N/AC:L/Au:N/C:C/I:C/A:C
|
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=538
http://osvdb.org/37236
http://osvdb.org/37237
http://secunia.com/advisories/25656
http://www.securityfocus.com/bid/24455
http://www.securitytracker.com/id?1018236
http://www.yabbforum.com/community/?board=general%3Baction=display%3Bnum=1181678785
https://exchange.xforce.ibmcloud.com/vulnerabilities/34848