Filtered by vendor Yabb Subscriptions
Filtered by product Yabb Subscriptions
Total 28 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2005-2296 1 Yabb 1 Yabb 2025-04-03 N/A
YabbSE 1.5.5c allows remote attackers to obtain sensitive information via a direct request to ssi_examples.php, which reveals the path.
CVE-2006-3275 1 Yabb 1 Yabb 2025-04-03 N/A
SQL injection vulnerability in profile.php in YaBB SE 1.5.5 and earlier allows remote attackers to execute SQL commands via a double-encoded user parameter in a viewprofile action.
CVE-2004-1662 1 Yabb 1 Yabb 2025-04-03 N/A
YaBB SE 1.5.1 allows remote attackers to obtain sensitive information via a direct HTTP request to Admin.php, which reveals the full path in a PHP error message.
CVE-2004-1827 2 Simple Machines, Yabb 2 Simple Machines Smf, Yabb 2025-04-03 N/A
Cross-site scripting (XSS) vulnerability in YaBB 1 Gold(SP1.3) and YaBB SE 1.5.1 Final allows remote attackers to inject arbitrary web script via the background:url property in (1) glow or (2) shadow tags.
CVE-2002-0117 1 Yabb 1 Yabb 2025-04-03 N/A
Cross-site scripting vulnerability in Yet Another Bulletin Board (YaBB) 1 Gold SP 1 and earlier allows remote attackers to execute arbitrary script and steal cookies via a message containing encoded Javascript in an IMG tag.
CVE-2002-2296 1 Yabb 1 Yabb 2025-04-03 N/A
Cross-site scripting (XSS) vulnerability in YaBB.pl in Yet Another Bulletin Board (YaBB) 1 Gold SP 1 allows remote attackers to inject arbitrary web script or HTML via the num parameter.
CVE-2005-0785 1 Yabb 1 Yabb 2025-04-03 N/A
Cross-site scripting (XSS) vulnerability in usersrecentposts in YaBB 2.0 rc1 allows remote attackers to inject arbitrary web script or HTML via the username parameter.
CVE-2013-2057 1 Yabb 1 Yabb 2024-11-21 9.8 Critical
YaBB through 2.5.2: 'guestlanguage' Cookie Parameter Local File Include Vulnerability