Search
Search Results (29 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 | 
|---|---|---|---|---|
| CVE-2003-1277 | 1 Yabb | 1 Yabb | 2025-04-03 | N/A | 
| Cross-site scripting (XSS) vulnerabilities in Yet Another Bulletin Board (YaBB) 1.5.0 allow remote attackers to execute arbitrary script as other users and possibly steal authentication information via cookies by injecting arbitrary HTML or script into (1) news_icon of news_template.php, and (2) threadid and subject of index.html | ||||
| CVE-2002-1845 | 1 Yabb | 1 Yabb | 2025-04-03 | N/A | 
| Cross-site scripting (XSS) vulnerability in index.php in Yet Another Bulletin Board (YaBB) 1.40 and 1.41 allows remote attackers to inject arbitrary web script or HTML via the password (passwrd) parameter. | ||||
| CVE-2004-1662 | 1 Yabb | 1 Yabb | 2025-04-03 | N/A | 
| YaBB SE 1.5.1 allows remote attackers to obtain sensitive information via a direct HTTP request to Admin.php, which reveals the full path in a PHP error message. | ||||
| CVE-2004-2754 | 1 Yabb | 1 Yabb Se | 2025-04-03 | N/A | 
| SQL injection vulnerability in SSI.php in YaBB SE 1.5.4, 1.5.3, and possibly other versions before 1.5.5 allows remote attackers to execute arbitrary SQL commands via the ID_MEMBER parameter to the (1) recentTopics and (2) welcome functions. | ||||
| CVE-2004-2402 | 1 Yabb | 1 Yabb | 2025-04-03 | N/A | 
| Cross-site scripting (XSS) vulnerability in YaBB.pl in YaBB 1 GOLD SP 1.3.2 allows remote attackers to inject arbitrary web script or HTML via a hex-encoded to parameter. NOTE: some sources say that the board parameter is affected, but this is incorrect. | ||||
| CVE-2004-2403 | 1 Yabb | 1 Yabb | 2025-04-03 | N/A | 
| Cross-site request forgery (CSRF) vulnerability in YaBB 1 GOLD SP 1.3.2 allows remote attackers to perform unauthorized actions as the administrative user via a link or IMG tag to YaBB.pl that specifies the desired action, id, and moda parameters. | ||||
| CVE-2005-0785 | 1 Yabb | 1 Yabb | 2025-04-03 | N/A | 
| Cross-site scripting (XSS) vulnerability in usersrecentposts in YaBB 2.0 rc1 allows remote attackers to inject arbitrary web script or HTML via the username parameter. | ||||
| CVE-2004-0291 | 1 Yabb | 1 Yabb | 2025-04-03 | N/A | 
| SQL injection vulnerability in post.php for YaBB SE 1.5.4 and 1.5.5 allows remote attackers to obtain hashed passwords via the quote parameter. | ||||
| CVE-2013-2057 | 1 Yabb | 1 Yabb | 2024-11-21 | 9.8 Critical | 
| YaBB through 2.5.2: 'guestlanguage' Cookie Parameter Local File Include Vulnerability | ||||