CVE-2007-3208

C

RLF injection vulnerability in Yet another Bulletin Board (YaBB) 2.1 allows remote attackers to obtain administrative access via requests to (1) register.pl or (2) profile.pl that write CRLF sequences to a .vars file. NOTE: this can be leveraged to execute arbitrary code.

Configurations

Configuration 1 (hide)

cpe:2.3:a:yabb:yabb:2.1:*:*:*:*:*:*:*

History

21 Nov 2024, 00:32

Type Values Removed Values Added
References () http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=538 - () http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=538 -
References () http://osvdb.org/37236 - () http://osvdb.org/37236 -
References () http://osvdb.org/37237 - () http://osvdb.org/37237 -
References () http://secunia.com/advisories/25656 - Patch, Vendor Advisory () http://secunia.com/advisories/25656 - Patch, Vendor Advisory
References () http://www.securityfocus.com/bid/24455 - Patch () http://www.securityfocus.com/bid/24455 - Patch
References () http://www.securitytracker.com/id?1018236 - () http://www.securitytracker.com/id?1018236 -
References () http://www.yabbforum.com/community/?board=general%3Baction=display%3Bnum=1181678785 - () http://www.yabbforum.com/community/?board=general%3Baction=display%3Bnum=1181678785 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/34848 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/34848 -

Information

Published : 2007-06-14 19:30

Updated : 2025-04-09 00:30


NVD link : CVE-2007-3208

Mitre link : CVE-2007-3208

CVE.ORG link : CVE-2007-3208


JSON object : View

Products Affected