CVE-2013-2057
- EPSS 2.02%
- Published 11.02.2020 18:15:15
- Last modified 21.11.2024 01:50:56
YaBB through 2.5.2: 'guestlanguage' Cookie Parameter Local File Include Vulnerability
CVE-2007-3295
- EPSS 1.45%
- Published 20.06.2007 21:30:00
- Last modified 09.04.2025 00:30:58
Directory traversal vulnerability in Yet another Bulletin Board (YaBB) 2.1 and earlier allows remote authenticated users to execute arbitrary Perl code via a .. (dot dot) in the userlanguage profile setting, which sets the userlanguage key of the mem...
- EPSS 17.12%
- Published 14.06.2007 19:30:00
- Last modified 09.04.2025 00:30:58
CRLF injection vulnerability in Yet another Bulletin Board (YaBB) 2.1 allows remote attackers to obtain administrative access via requests to (1) register.pl or (2) profile.pl that write CRLF sequences to a .vars file. NOTE: this can be leveraged to...
CVE-2006-4157
- EPSS 0.42%
- Published 16.08.2006 22:04:00
- Last modified 03.04.2025 01:03:51
Cross-site scripting (XSS) vulnerability in index.php in Yet another Bulletin Board (YaBB) allows remote attackers to inject arbitrary web script or HTML via the categories parameter.
CVE-2006-3275
- EPSS 0.62%
- Published 28.06.2006 22:05:00
- Last modified 03.04.2025 01:03:51
SQL injection vulnerability in profile.php in YaBB SE 1.5.5 and earlier allows remote attackers to execute SQL commands via a double-encoded user parameter in a viewprofile action.
- EPSS 0.24%
- Published 20.12.2005 11:03:00
- Last modified 03.04.2025 01:03:51
Interpretation conflict in YaBB before 2.1 allows remote authenticated users to inject arbitrary web script or HTML via HTML in a file with a GIF file extension, which causes the HTML to be executed by a victim who views the file in Internet Explorer...
- EPSS 0.35%
- Published 18.07.2005 04:00:00
- Last modified 03.04.2025 01:03:51
YabbSE 1.5.5c allows remote attackers to obtain sensitive information via a direct request to ssi_examples.php, which reveals the path.
CVE-2005-0785
- EPSS 0.41%
- Published 02.05.2005 04:00:00
- Last modified 03.04.2025 01:03:51
Cross-site scripting (XSS) vulnerability in usersrecentposts in YaBB 2.0 rc1 allows remote attackers to inject arbitrary web script or HTML via the username parameter.
CVE-2005-0741
- EPSS 0.49%
- Published 08.03.2005 05:00:00
- Last modified 03.04.2025 01:03:51
Cross-site scripting (XSS) vulnerability in YaBB.pl for YaBB 2.0 RC1 allows remote attackers to inject arbitrary web script or HTML via the username parameter in a usersrecentposts action.
- EPSS 1.45%
- Published 31.12.2004 05:00:00
- Last modified 03.04.2025 01:03:51
Cross-site request forgery (CSRF) vulnerability in YaBB 1 GOLD SP 1.3.2 allows remote attackers to perform unauthorized actions as the administrative user via a link or IMG tag to YaBB.pl that specifies the desired action, id, and moda parameters.