Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-3208

Опубликовано: 14 июн. 2007
Источник: nvd
CVSS2: 10
EPSS Средний

Описание

CRLF injection vulnerability in Yet another Bulletin Board (YaBB) 2.1 allows remote attackers to obtain administrative access via requests to (1) register.pl or (2) profile.pl that write CRLF sequences to a .vars file. NOTE: this can be leveraged to execute arbitrary code.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:yabb:yabb:2.1:*:*:*:*:*:*:*

EPSS

Процентиль: 95%
0.17673
Средний

10 Critical

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
почти 4 года назад

CRLF injection vulnerability in Yet another Bulletin Board (YaBB) 2.1 allows remote attackers to obtain administrative access via requests to (1) register.pl or (2) profile.pl that write CRLF sequences to a .vars file. NOTE: this can be leveraged to execute arbitrary code.

EPSS

Процентиль: 95%
0.17673
Средний

10 Critical

CVSS2

Дефекты

NVD-CWE-Other