Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.11588
Category:CGI abuses
Title:YaBB SE command execution
Summary:NOSUMMARY
Description:Description:

The remote host is using the YaBB SE forum management system.

According to its version number, this forum is vulnerable to a
code injection bug which may allow an attacker with a valid account
to execute arbitrary commands on this host by sending a malformed
'language' parameter in the web request.

In addition to this flaw, this version is vulnerable to other flaws
such as SQL injection.

Solution: Upgrade to YaBB SE 1.5.2 or newer
Risk factor : High

Cross-Ref: BugTraq ID: 1921
BugTraq ID: 6591
BugTraq ID: 6663
BugTraq ID: 6674
BugTraq ID: 7399
Common Vulnerability Exposure (CVE) ID: CVE-2000-1176
http://www.securityfocus.com/bid/1921
Bugtraq: 20001107 Insecure input balidation in YaBB Search.pl (Google Search)
http://archives.neohapsis.com/archives/bugtraq/2000-11/0110.html
CopyrightThis script is Copyright (C) 2003 Renaud Deraison

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.