Vulnerabilities > CVE-2006-3275 - Unspecified vulnerability in Yabb 1.5.1/1.5.2/1.5.4
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
SQL injection vulnerability in profile.php in YaBB SE 1.5.5 and earlier allows remote attackers to execute SQL commands via a double-encoded user parameter in a viewprofile action.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 4 |
References
- http://marc.info/?l=full-disclosure&m=115102378824221&w=2
- http://marc.info/?l=full-disclosure&m=115102378824221&w=2
- http://secunia.com/advisories/20780
- http://secunia.com/advisories/20780
- http://www.securityfocus.com/bid/18625
- http://www.securityfocus.com/bid/18625
- http://www.vupen.com/english/advisories/2006/2504
- http://www.vupen.com/english/advisories/2006/2504
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27331
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27331