peter bassill · operator
$ cve CVE-2004-2754 JSON

CVE-2004-2754 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 2.4% (pctl 83)

Patch early

A public exploit exists.

Description

SQL injection vulnerability in SSI.php in YaBB SE 1.5.4, 1.5.3, and possibly other versions before 1.5.5 allows remote attackers to execute arbitrary SQL commands via the ID_MEMBER parameter to the (1) recentTopics and (2) welcome functions.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS2.35% — more likely to be exploited than 83% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2004-12-31
Last modified2026-06-16

Affected (1)

VendorProduct
yabbyabb se

Public exploits

SourceTitleDate
exploit-dbYABB SE 1.x - 'SSI.php' ID_MEMBER SQL Injection2004-01-19

References

→ the Explorer  ·  watch your stack  ·  NVD