Vulnerabilities > Yabb > Yabb > 1.gold.sp.1

DATE CVE VULNERABILITY TITLE RISK
2005-12-20 CVE-2005-4426 HTML Injection vulnerability in YaBB Image Upload
Interpretation conflict in YaBB before 2.1 allows remote authenticated users to inject arbitrary web script or HTML via HTML in a file with a GIF file extension, which causes the HTML to be executed by a victim who views the file in Internet Explorer as a result of CVE-2005-3312.
network
low complexity
yabb
4.0
2004-12-31 CVE-2004-2403 Unspecified vulnerability in Yabb
Cross-site request forgery (CSRF) vulnerability in YaBB 1 GOLD SP 1.3.2 allows remote attackers to perform unauthorized actions as the administrative user via a link or IMG tag to YaBB.pl that specifies the desired action, id, and moda parameters.
network
low complexity
yabb
critical
10.0
2004-12-31 CVE-2004-2402 Cross-Site Scripting vulnerability in YaBB YaBB.pl IMSend
Cross-site scripting (XSS) vulnerability in YaBB.pl in YaBB 1 GOLD SP 1.3.2 allows remote attackers to inject arbitrary web script or HTML via a hex-encoded to parameter.
network
yabb
4.3
2002-12-31 CVE-2002-2296 Cross-Site Scripting vulnerability in Yabb 1Goldsp1
Cross-site scripting (XSS) vulnerability in YaBB.pl in Yet Another Bulletin Board (YaBB) 1 Gold SP 1 allows remote attackers to inject arbitrary web script or HTML via the num parameter.
network
yabb CWE-79
4.3
2002-10-04 CVE-2002-0955 Cross-Site Scripting vulnerability in Yabb 1Goldsp1
Cross-site scripting vulnerability in YaBB.cgi for Yet Another Bulletin Board (YaBB) 1 Gold SP1 and earlier allows remote attackers to execute arbitrary script as other web site visitors via script in the num parameter, which is not filtered in the resulting error message.
network
low complexity
yabb
7.5