Yabb

Yabb

27 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 2.02%
  • Veröffentlicht 11.02.2020 18:15:15
  • Zuletzt bearbeitet 21.11.2024 01:50:56

YaBB through 2.5.2: 'guestlanguage' Cookie Parameter Local File Include Vulnerability

  • EPSS 1.45%
  • Veröffentlicht 20.06.2007 21:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Directory traversal vulnerability in Yet another Bulletin Board (YaBB) 2.1 and earlier allows remote authenticated users to execute arbitrary Perl code via a .. (dot dot) in the userlanguage profile setting, which sets the userlanguage key of the mem...

  • EPSS 17.12%
  • Veröffentlicht 14.06.2007 19:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

CRLF injection vulnerability in Yet another Bulletin Board (YaBB) 2.1 allows remote attackers to obtain administrative access via requests to (1) register.pl or (2) profile.pl that write CRLF sequences to a .vars file. NOTE: this can be leveraged to...

Exploit
  • EPSS 0.42%
  • Veröffentlicht 16.08.2006 22:04:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Cross-site scripting (XSS) vulnerability in index.php in Yet another Bulletin Board (YaBB) allows remote attackers to inject arbitrary web script or HTML via the categories parameter.

  • EPSS 0.62%
  • Veröffentlicht 28.06.2006 22:05:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

SQL injection vulnerability in profile.php in YaBB SE 1.5.5 and earlier allows remote attackers to execute SQL commands via a double-encoded user parameter in a viewprofile action.

  • EPSS 0.24%
  • Veröffentlicht 20.12.2005 11:03:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Interpretation conflict in YaBB before 2.1 allows remote authenticated users to inject arbitrary web script or HTML via HTML in a file with a GIF file extension, which causes the HTML to be executed by a victim who views the file in Internet Explorer...

  • EPSS 0.35%
  • Veröffentlicht 18.07.2005 04:00:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

YabbSE 1.5.5c allows remote attackers to obtain sensitive information via a direct request to ssi_examples.php, which reveals the path.

Exploit
  • EPSS 0.41%
  • Veröffentlicht 02.05.2005 04:00:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Cross-site scripting (XSS) vulnerability in usersrecentposts in YaBB 2.0 rc1 allows remote attackers to inject arbitrary web script or HTML via the username parameter.

Exploit
  • EPSS 0.49%
  • Veröffentlicht 08.03.2005 05:00:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Cross-site scripting (XSS) vulnerability in YaBB.pl for YaBB 2.0 RC1 allows remote attackers to inject arbitrary web script or HTML via the username parameter in a usersrecentposts action.

Exploit
  • EPSS 1.45%
  • Veröffentlicht 31.12.2004 05:00:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Cross-site request forgery (CSRF) vulnerability in YaBB 1 GOLD SP 1.3.2 allows remote attackers to perform unauthorized actions as the administrative user via a link or IMG tag to YaBB.pl that specifies the desired action, id, and moda parameters.