Vulnerabilities > Yabb > Yabb > 1.5.1

DATE CVE VULNERABILITY TITLE RISK
2006-08-16 CVE-2006-4157 Cross-Site Scripting vulnerability in YaBBSE
Cross-site scripting (XSS) vulnerability in index.php in Yet another Bulletin Board (YaBB) allows remote attackers to inject arbitrary web script or HTML via the categories parameter.
network
yabb
6.8
2006-06-28 CVE-2006-3275 SQL Injection vulnerability in Yabb 1.5.1/1.5.2/1.5.4
SQL injection vulnerability in profile.php in YaBB SE 1.5.5 and earlier allows remote attackers to execute SQL commands via a double-encoded user parameter in a viewprofile action.
network
low complexity
yabb
7.5
2004-08-25 CVE-2004-1662 YaBB SE 1.5.1 allows remote attackers to obtain sensitive information via a direct HTTP request to Admin.php, which reveals the full path in a PHP error message.
network
low complexity
yabb
5.0