VulnerabilityModified
CVE-2004-1982
Post.pl in YaBB 1 Gold SP 1.2 allows remote attackers to modify records in the board's .txt file via carriage return characters in the subject field.
MEDIUM 5.0EPSS 1.46%
Does this matter?
Lower severity and a low EPSS score (1.46%). Track it; it rarely justifies an emergency change on its own.
Description
Post.pl in YaBB 1 Gold SP 1.2 allows remote attackers to modify records in the board's .txt file via carriage return characters in the subject field.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 1.46% probability · 72th percentile
- CISA KEV
- Not listed
- Affected
- yabb/yabb
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=108360430703935&w=2
- http://secunia.com/advisories/12609Exploit, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/10263Exploit, Patch, Vendor Advisory
- http://www.yabbforum.com/community/YaBB.pl?board=general%3Baction=display%3Bnum=1093133233
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16050
- http://marc.info/?l=bugtraq&m=108360430703935&w=2
- http://secunia.com/advisories/12609Exploit, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/10263Exploit, Patch, Vendor Advisory
- http://www.yabbforum.com/community/YaBB.pl?board=general%3Baction=display%3Bnum=1093133233
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16050
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.