peter bassill · operator
$ cve CVE-2004-0291 JSON

CVE-2004-0291 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 1.4% (pctl 72)

Patch early

A public exploit exists.

Description

SQL injection vulnerability in post.php for YaBB SE 1.5.4 and 1.5.5 allows remote attackers to obtain hashed passwords via the quote parameter.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS1.42% — more likely to be exploited than 72% of all CVEs
On CISA KEVno
Public exploityes
Published2004-11-23
Last modified2026-06-16

Affected (1)

VendorProduct
yabbyabb

Public exploits

SourceTitleDate
exploit-dbYABB SE 1.5 - 'Quote' SQL Injection2004-02-16

References

→ the Explorer  ·  watch your stack  ·  NVD