Lucene search

K
cve[email protected]CVE-2004-0343
HistoryNov 23, 2004 - 5:00 a.m.

CVE-2004-0343

2004-11-2305:00:00
web.nvd.nist.gov
26
sql injection
yabb se
vulnerability
cve-2004-0343
remote execution

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

8.7 High

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

60.4%

Multiple SQL injection vulnerabilities in YaBB SE 1.5.4 through 1.5.5b allow remote attackers to execute arbitrary SQL via (1) the msg parameter in ModifyMessage.php or (2) the postid parameter in ModifyMessage.php.

Affected configurations

NVD
Node
yabbyabbMatch1.5.4second_edition
OR
yabbyabbMatch1.5.5second_edition
OR
yabbyabbMatch1.5.5bsecond_edition

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

8.7 High

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

60.4%

Related for CVE-2004-0343