CVE Vulnerabilities

CVE-2004-0343

Published: Nov 23, 2004 | Modified: Jul 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Multiple SQL injection vulnerabilities in YaBB SE 1.5.4 through 1.5.5b allow remote attackers to execute arbitrary SQL via (1) the msg parameter in ModifyMessage.php or (2) the postid parameter in ModifyMessage.php.

Affected Software

Name Vendor Start Version End Version
Yabb Yabb 1.5.5 1.5.5
Yabb Yabb 1.5.5b 1.5.5b
Yabb Yabb 1.5.4 1.5.4

References