Cross-site scripting (XSS) vulnerability in index.php in Yet Another Bulletin Board (YaBB) 1.40 and 1.41 allows remote attackers to inject arbitrary web script or HTML via the password (passwrd) parameter.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Yabb | Yabb | 1.40 (including) | 1.40 (including) |
| Yabb | Yabb | 1.41 (including) | 1.41 (including) |