peter bassill · operator
$ cve CVE-2004-0343 JSON

CVE-2004-0343 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 1.8% (pctl 78)

Patch early

A public exploit exists.

Description

Multiple SQL injection vulnerabilities in YaBB SE 1.5.4 through 1.5.5b allow remote attackers to execute arbitrary SQL via (1) the msg parameter in ModifyMessage.php or (2) the postid parameter in ModifyMessage.php.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS1.84% — more likely to be exploited than 78% of all CVEs
On CISA KEVno
Public exploityes
Published2004-11-23
Last modified2026-06-16

Affected (1)

VendorProduct
yabbyabb

Public exploits

SourceTitleDate
exploit-dbYaBB SE 1.5.x - Multiple SQL Injections2004-03-01

References

→ the Explorer  ·  watch your stack  ·  NVD