SQL injection vulnerability in profile.php in YaBB SE 1.5.5 and earlier allows remote attackers to execute SQL commands via a double-encoded user parameter in a viewprofile action.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Yabb | Yabb | * | 1.5.5 (including) |
Yabb | Yabb | 1.5.1 (including) | 1.5.1 (including) |
Yabb | Yabb | 1.5.2 (including) | 1.5.2 (including) |
Yabb | Yabb | 1.5.4 (including) | 1.5.4 (including) |