Vulnerability index

Browse CVEs

20 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Yabb CRITICAL 9.8
CVE-2013-2057

YaBB through 2.5.2: 'guestlanguage' Cookie Parameter Local File Include Vulnerability

Fix: after 2.5.2
Fix from $2,300 2020-02-11
Yabb MEDIUM 6.5
CVE-2007-3295

Directory traversal vulnerability in Yet another Bulletin Board (YaBB) 2.1 and earlier allows remote authenticated users to execute arbitrary Perl co…

Mitigation only
Fix from $1,600 2007-06-20
Yabb HIGH 10.0
CVE-2007-3208EPSS 6%

CRLF injection vulnerability in Yet another Bulletin Board (YaBB) 2.1 allows remote attackers to obtain administrative access via requests to (1) reg…

Patch available
Fix from $1,950 2007-06-14
Yabb MEDIUM 6.8
CVE-2006-4157

Cross-site scripting (XSS) vulnerability in index.php in Yet another Bulletin Board (YaBB) allows remote attackers to inject arbitrary web script or …

No fix yet
Fix from $1,600 2006-08-16
Yabb HIGH 7.5
CVE-2006-3275

SQL injection vulnerability in profile.php in YaBB SE 1.5.5 and earlier allows remote attackers to execute SQL commands via a double-encoded user par…

Fix: after 1.5.5
Fix from $1,950 2006-06-28
Yabb MEDIUM 5.0
CVE-2005-2296

YabbSE 1.5.5c allows remote attackers to obtain sensitive information via a direct request to ssi_examples.php, which reveals the path.

Mitigation only
Fix from $1,600 2005-07-18
Yabb HIGH 10.0
CVE-2004-2403

Cross-site request forgery (CSRF) vulnerability in YaBB 1 GOLD SP 1.3.2 allows remote attackers to perform unauthorized actions as the administrative…

No fix yet
Fix from $1,950 2004-12-31
Yabb HIGH 7.5
CVE-2004-2139

Unknown vulnerability in Adminedit.pl YaBB 1 Gold before 1.3.2 allows attackers to execute arbitrary code via settings.pl.

Patch available
Fix from $1,950 2004-12-31
Yabb Se HIGH 7.5
CVE-2004-2754

SQL injection vulnerability in SSI.php in YaBB SE 1.5.4, 1.5.3, and possibly other versions before 1.5.5 allows remote attackers to execute arbitrary…

Patch available
Fix from $1,950 2004-12-31
Yabb MEDIUM 5.0
CVE-2004-2140

CRLF injection vulnerability in YaBB 1 Gold before 1.3.2 allows remote attackers to modify text file contents via the subject variable.

Patch available
Fix from $1,600 2004-12-31
Yabb HIGH 10.0
CVE-2004-0343

Multiple SQL injection vulnerabilities in YaBB SE 1.5.4 through 1.5.5b allow remote attackers to execute arbitrary SQL via (1) the msg parameter in M…

Patch available
Fix from $1,950 2004-11-23
Yabb MEDIUM 6.4
CVE-2004-0344

Directory traversal vulnerability in ModifyMessage.php in YaBB SE 1.5.4 through 1.5.5b allows remote attackers to delete arbitrary files via a .. (do…

Patch available
Fix from $1,600 2004-11-23
Yabb MEDIUM 5.0
CVE-2004-0291

SQL injection vulnerability in post.php for YaBB SE 1.5.4 and 1.5.5 allows remote attackers to obtain hashed passwords via the quote parameter.

Patch available
Fix from $1,600 2004-11-23
Yabb MEDIUM 5.0
CVE-2004-1982

Post.pl in YaBB 1 Gold SP 1.2 allows remote attackers to modify records in the board's .txt file via carriage return characters in the subject field.

Patch available
Fix from $1,600 2004-05-03
Yabb MEDIUM 5.1
CVE-2003-0275

SSI.php in YaBB SE 1.5.2 allows remote attackers to execute arbitrary PHP code by modifying the sourcedir parameter to reference a URL on a remote we…

Mitigation only
Fix from $1,600 2003-06-16
Yabb MEDIUM 5.0
CVE-2002-1846

Yet Another Bulletin Board (YaBB) 1.40 and 1.41 does not require a user to submit the correct password before changing it to a new password, which al…

Mitigation only
Fix from $1,600 2002-12-31
Yabb HIGH 7.5
CVE-2002-0955EPSS 9%

Cross-site scripting vulnerability in YaBB.cgi for Yet Another Bulletin Board (YaBB) 1 Gold SP1 and earlier allows remote attackers to execute arbitr…

No fix yet
Fix from $1,950 2002-10-04
Yabb HIGH 7.5
CVE-2002-0117

Cross-site scripting vulnerability in Yet Another Bulletin Board (YaBB) 1 Gold SP 1 and earlier allows remote attackers to execute arbitrary script a…

Patch available
Fix from $1,950 2002-03-25
Yabb HIGH 7.5
CVE-2000-1176EPSS 6%

Directory traversal vulnerability in YaBB search.pl CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack in the "cats…

No fix yet
Fix from $1,950 2001-01-09
Yabb MEDIUM 5.0
CVE-2000-0853EPSS 8%

YaBB Bulletin Board 9.1.2000 allows remote attackers to read arbitrary files via a .. (dot dot) attack.

Patch available
Fix from $1,600 2000-11-14