CVE-2004-2754 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 2.4% (pctl 83)
Patch early
A public exploit exists.
Description
SQL injection vulnerability in SSI.php in YaBB SE 1.5.4, 1.5.3, and possibly other versions before 1.5.5 allows remote attackers to execute arbitrary SQL commands via the ID_MEMBER parameter to the (1) recentTopics and (2) welcome functions.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 2.35% — more likely to be exploited than 83% of all CVEs |
| Weakness | CWE-89 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2004-12-31 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| yabb | yabb se |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | YABB SE 1.x - 'SSI.php' ID_MEMBER SQL Injection | 2004-01-19 |
References
- http://securityreason.com/securityalert/3371
- http://sourceforge.net/project/shownotes.php?release_id=210608&group_id=57105
- http://www.osvdb.org/3618
- http://www.securityfocus.com/archive/1/350244
- http://www.securityfocus.com/bid/9449
- http://www.securitytracker.com/id?1008764
- http://www.yabbse.org/community/index.php?thread=27122
- http://securityreason.com/securityalert/3371
- http://sourceforge.net/project/shownotes.php?release_id=210608&group_id=57105
- http://www.osvdb.org/3618
- http://www.securityfocus.com/archive/1/350244
- http://www.securityfocus.com/bid/9449
- http://www.securitytracker.com/id?1008764
- http://www.yabbse.org/community/index.php?thread=27122
→ the Explorer · watch your stack · NVD