| OSVDB ID | Disclosure Date | Title |
|
3618
Description:
YaBB SE contains a flaw that will allow an attacker to inject arbitrary SQL code. The problem is that the ID_MEMBER variable in the SSI.php module is not verified properly and will allow an attacker to inject or manipulate SQL queries through the welcome or recentTopics functions.
|
2004-01-20
|
YaBB SE SSI.php ID_MEMBER Parameter SQL Injection
|
|
6678
Description:
(Description Provided by CVE) : SSI.php in YaBB SE 1.5.2 allows remote attackers to execute arbitrary PHP code by modifying the sourcedir parameter to reference a URL on a remote web server that contains the code.
|
2003-05-09
|
YaBB SE SSI.php sourcedir Arbitrary Command Execution
|
|
18242
Description:
(Description Provided by CVE) : YabbSE 1.5.5c allows remote attackers to obtain sensitive information via a direct request to ssi_examples.php, which reveals the path.
|
2005-07-14
|
YaBB SE ssi_examples.php Direct Request Path Disclosure
|
|
50427
Description:
Unknown / Incomplete
|
2008-01-22
|
YaBB SE YaBBSE155 Cookie Authentication Bypass
|
|
7697
Description:
(Description Provided by CVE) : Directory traversal vulnerability in YaBB search.pl CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack in the "catsearch" form field.
|
2000-11-07
|
YaBB search.pl catsearch Parameter Traversal Arbitrary File Access
|
|
12145
Description:
YaBB Gold contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate user input using the "shadow" BBCode formatting tag. This could allow a malicious user to submit a specially crafted message that, when viewed by a target, would execute arbitrary code in the target's browser, leading to a loss of integrity.
|
2004-11-25
|
YaBB Shadow BBCode Tag XSS
|
|
10221
Description:
YaBB Gold contains a flaw that may allow a malicious user to insert line breaks in a related text file. The issue is triggered when malicious input in the subject variable occurs. It is possible that the flaw may allow manipulate a text file resulting in a loss of integrity.
|
2004-09-22
|
YaBB Subject Variable Line Break Content Manipulation
|
|
6724
Description:
(Description Provided by CVE) : YaBB 1 SP 1.3.1 displays different error messages when a user exists or not, which makes it easier for remote attackers to identify valid users and conduct a brute force password guessing attack.
|
2004-02-17
|
YaBB Valid User Information Disclosure
|
|
9234
Description:
(Description Provided by CVE) : Cross-site scripting vulnerability in YaBB.cgi for Yet Another Bulletin Board (YaBB) 1 Gold SP1 and earlier allows remote attackers to execute arbitrary script as other web site visitors via script in the num parameter, which is not filtered in the resulting error message.
|
2002-06-21
|
YaBB YaBB.cgi num Parameter XSS
|
|
10243
Description:
(Description Provided by CVE) : Cross-site request forgery (CSRF) vulnerability in YaBB 1 GOLD SP 1.3.2 allows remote attackers to perform unauthorized actions as the administrative user via a link or IMG tag to YaBB.pl that specifies the desired action, id, and moda parameters.
|
2004-09-16
|
YaBB YaBB.pl CSRF IMG Tag Command Injection
|
|
411
Description:
YaBB contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'YaBB.pl' script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied to the 'num' parameter. This may allow an attacker to include a file from the targeted host that contains arbitrary commands or code that will be executed by the vulnerable script. Such attacks are limited due to the script only calling files already on the target host. In addition, this flaw can potentially be used to disclose the contents of any file on the system accessible by the web server.
|
2000-09-09
|
YaBB YaBB.pl num Parameter Traversal Arbitrary File Access
|
|
41022
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in YaBB.pl in Yet Another Bulletin Board (YaBB) 1 Gold SP 1 allows remote attackers to inject arbitrary web script or HTML via the num parameter.
|
2002-12-01
|
YaBB YaBB.pl num Parameter XSS
|
|
10242
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in YaBB.pl in YaBB 1 GOLD SP 1.3.2 allows remote attackers to inject arbitrary web script or HTML via a hex-encoded to parameter. NOTE: some sources say that the board parameter is affected, but this is incorrect.
|
2004-09-16
|
YaBB YaBB.pl to Parameter XSS
|
|
10220
Description:
Unknown / Incomplete
|
2004-09-22
|
YaBB YaBBC.pl glow/shadow Tag Arbitrary Java Code Execution
|
|
14827
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in YaBB.pl for YaBB 2.0 RC1 allows remote attackers to inject arbitrary web script or HTML via the username parameter in a usersrecentposts action.
|
2005-03-13
|
YaBB2 YaBB.pl usersrecentposts Action username Parameter XSS
|
|
82543
Description:
YABSoft Advanced Image Hosting contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the view_comments.php script not properly sanitizing user-supplied input to the 'gal' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2012-01-12
|
YABSoft Advanced Image Hosting Script view_comments.php gal Parameter SQL Injection
|
|
52789
Description:
YABSoft Mega File Hosting Script contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'cross.php' script not properly sanitizing user input supplied to the 'url' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2009-03-17
|
YABSoft Mega File Hosting Script cross.php url Parameter Remote File Inclusion
|
|
58889
Description:
YABSoft Mega File Hosting Script contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate 'moudi' parameters upon submission to the 'emaullinks.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2009-09-16
|
YABSoft Mega File Hosting Script emaullinks.php moudi Parameter XSS
|
|
45036
Description:
YABSoft Mega File Hosting Script contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'members.php' script not properly sanitizing user-supplied input to the 'fid' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2008-05-12
|
YABSoft Mega File Hosting Script members.php fid Parameter SQL Injection
|
|
47080
Description:
(Description Provided by CVE) : skeleton.c in yacc does not properly handle reduction of a rule with an empty right hand side, which allows context-dependent attackers to cause an out-of-bounds stack access when the yacc stack pointer points to the end of the stack.
|
2008-07-08
|
Yacc skeleton.c yyparse() Function Parsed Rule DoS
|
|
67149
Description:
YACK CMS contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'index.php' script not properly sanitizing user input supplied to the 'context[path_to_root]' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2010-07-17
|
YACK CMS index.php context[path_to_root] Parameter Remote File Inclusion
|
|
71292
Description:
YaCOMAS contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'S_login' parameter upon submission to the admin/index.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-03-30
|
YaCOMAS admin/index.php S_login Parameter XSS
|
|
71291
Description:
YaCOMAS contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'S_login', 'S_nombrep', 'S_apellidos', 'S_mail', 'S_org' and 'S_ciudad' parameters upon submission to the asistente/index.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2011-03-30
|
YaCOMAS asistente/index.php Multiple Parameter XSS
|
|
28301
Description:
YACS contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to article.php not properly sanitizing user input supplied to the 'context[path_to_root]' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-08-31
|
YACS article.php context[path_to_root] Parameter Remote File Inclusion
|
|
31301
Description:
YACS contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'context[path_to_root]' variable upon submission to the 'articles/populate.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-08-29
|
YACS articles/populate.php context[path_to_root] Parameter Remote File Inclusion
|
|
31302
Description:
YACS contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'context[path_to_root]' variable upon submission to the 'categories/category.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-08-29
|
YACS categories/category.php context[path_to_root] Parameter Remote File Inclusion
|
|
31303
Description:
YACS contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'context[path_to_root]' variable upon submission to the 'categories/populate.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-08-29
|
YACS categories/populate.php context[path_to_root] Parameter Remote File Inclusion
|
|
31304
Description:
YACS contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'context[path_to_root]' variable upon submission to the 'comments/populate.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-08-29
|
YACS comments/populate.php context[path_to_root] Parameter Remote File Inclusion
|
|
31305
Description:
YACS contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'context[path_to_root]' variable upon submission to the 'files/file.php' script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2006-08-29
|
YACS files/file.php context[path_to_root] Parameter Remote File Inclusion
|
|
52041
Description:
YACS contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to scripts/update_trailer.php not properly sanitizing user input supplied to the context[path_to_root] parameter. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2009-02-16
|
YACS scripts/update_trailer.php context[path_to_root] Parameter Remote File Inclusion
|