CVE Vulnerabilities

CVE-2004-2403

Published: Dec 31, 2004 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Cross-site request forgery (CSRF) vulnerability in YaBB 1 GOLD SP 1.3.2 allows remote attackers to perform unauthorized actions as the administrative user via a link or IMG tag to YaBB.pl that specifies the desired action, id, and moda parameters.

Affected Software

NameVendorStart VersionEnd Version
YabbYabb1.40 (including)1.40 (including)
YabbYabb1.41 (including)1.41 (including)
YabbYabb1_gold_-_sp_1 (including)1_gold_-_sp_1 (including)
YabbYabb1_gold_-_sp_1.2 (including)1_gold_-_sp_1.2 (including)
YabbYabb1_gold_-_sp_1.3 (including)1_gold_-_sp_1.3 (including)
YabbYabb1_gold_-_sp_1.3.1 (including)1_gold_-_sp_1.3.1 (including)
YabbYabb1_gold_-_sp_1.3.2 (including)1_gold_-_sp_1.3.2 (including)
YabbYabb1_gold_release (including)1_gold_release (including)
YabbYabb2000-09-01 (including)2000-09-01 (including)
YabbYabb2000-09-11 (including)2000-09-11 (including)

References