Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8v86-544p-jvp9

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

CRLF injection vulnerability in Yet another Bulletin Board (YaBB) 2.1 allows remote attackers to obtain administrative access via requests to (1) register.pl or (2) profile.pl that write CRLF sequences to a .vars file. NOTE: this can be leveraged to execute arbitrary code.

CRLF injection vulnerability in Yet another Bulletin Board (YaBB) 2.1 allows remote attackers to obtain administrative access via requests to (1) register.pl or (2) profile.pl that write CRLF sequences to a .vars file. NOTE: this can be leveraged to execute arbitrary code.

EPSS

Процентиль: 95%
0.17673
Средний

Связанные уязвимости

nvd
больше 18 лет назад

CRLF injection vulnerability in Yet another Bulletin Board (YaBB) 2.1 allows remote attackers to obtain administrative access via requests to (1) register.pl or (2) profile.pl that write CRLF sequences to a .vars file. NOTE: this can be leveraged to execute arbitrary code.

EPSS

Процентиль: 95%
0.17673
Средний