CVE-2004-0343 EXPLOIT
10.0
HIGH · CVSS 2.0 · EPSS 1.8% (pctl 78)
Patch early
A public exploit exists.
Description
Multiple SQL injection vulnerabilities in YaBB SE 1.5.4 through 1.5.5b allow remote attackers to execute arbitrary SQL via (1) the msg parameter in ModifyMessage.php or (2) the postid parameter in ModifyMessage.php.
Scoring
| CVSS | 10.0 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| EPSS | 1.84% — more likely to be exploited than 78% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2004-11-23 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| yabb | yabb |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | YaBB SE 1.5.x - Multiple SQL Injections | 2004-03-01 |
References
→ the Explorer · watch your stack · NVD