| OSVDB ID | Disclosure Date | Title |
|
37402
Description:
(Description Provided by CVE) : Multiple cross-site scripting (XSS) vulnerabilities in iletisim.asp in Y&K Iletisim Formu allow remote attackers to inject arbitrary web script or HTML via the (1) ad, (2) sehir, (3) yas, (4) cins, (5) tel, (6) mail, and (7) mesaj parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
|
2007-10-01
|
Y&K Iletism Formu iletisim.asp Multiple Parameter XSS
|
|
18133
Description:
(Description Provided by CVE) : Y.SAK allows remote attackers to execute arbitrary commands via shell metacharacters in the $no variable to (1) w_s3mbfm.cgi, (2) w_s3adix.cgi, or (3) w_s3sbfm.cgi.
|
2005-07-16
|
Y.SAK Scripts w_s3adix.cgi Arbitrary Command Execution
|
|
18132
Description:
(Description Provided by CVE) : Y.SAK allows remote attackers to execute arbitrary commands via shell metacharacters in the $no variable to (1) w_s3mbfm.cgi, (2) w_s3adix.cgi, or (3) w_s3sbfm.cgi.
|
2005-07-16
|
Y.SAK Scripts w_s3mbfm.cgi Arbitrary Command Execution
|
|
18134
Description:
(Description Provided by CVE) : Y.SAK allows remote attackers to execute arbitrary commands via shell metacharacters in the $no variable to (1) w_s3mbfm.cgi, (2) w_s3adix.cgi, or (3) w_s3sbfm.cgi.
|
2005-07-16
|
Y.SAK Scripts w_s3sbfm.cgi Arbitrary Command Execution
|
|
35519
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in YA Book 0.98-alpha allows remote attackers to inject arbitrary web script or HTML via the City field in a sign action in index.php.
|
2007-04-24
|
YA Book index.php Sign Action XSS
|
|
36060
Description:
YAAP contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'includes/common.php' script not properly sanitizing user input supplied to the 'root_path' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2007-05-12
|
YAAP includes/common.php root_path Parameter Remote File Inclusion
|
|
10222
Description:
YaBB contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate an unspecified variable upon submission to the adminedit.pl script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-09-22
|
YaBB Adminedit.pl Settings Arbitrary Code Execution
|
|
4283
Description:
YaBB and Simple Machines SMF contain a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate user input upon submission to the "glow" or "shadow" formatting tags. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-02-29
|
YaBB background:url glow / shadow Tag XSS
|
|
45279
Description:
(Description Provided by CVE) : Yet Another Bulletin Board (YaBB) 1.40 and 1.41 does not require a user to submit the correct password before changing it to a new password, which allows remote attackers to modify passwords by stealing the cookie of another user, modifying the expiretime setting, and submitting the change in a profile2 action to index.php.
|
2002-10-18
|
YaBB Current Password Change Weakness
|
|
20686
Description:
Unknown / Incomplete
|
2005-11-08
|
YaBB Gmod Arbitrary Privileged Profile Modification
|
|
67635
Description:
Unknown / Incomplete
|
2010-02-08
|
YaBB Hashed Password Salt Weakness Crafted Cookie Authentication Bypass
|
|
2019
Description:
YaBB contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate content inserted into [IMG][/IMG] image links upon submission to the script that handles forum messages and replies. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2002-01-08
|
YaBB IMG Tag XSS
|
|
38021
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerabilities in Yet Another Bulletin Board (YaBB) 1.5.0 allow remote attackers to execute arbitrary script as other users and possibly steal authentication information via cookies by injecting arbitrary HTML or script into (1) news_icon of news_template.php, and (2) threadid and subject of index.html
|
2003-01-05
|
YaBB index.html threadid Parameter XSS
|
|
31694
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in index.php in Yet Another Bulletin Board (YaBB) 1.40 and 1.41 allows remote attackers to inject arbitrary web script or HTML via the password (passwrd) parameter.
|
2002-10-18
|
YaBB index.php password Parameter XSS
|
|
93045
Description:
YaBB contains a flaw that is due to the program failing to properly verify input passed via the guestlanguage cookie upon submission to Load.pl before being used in a local file inclusion. This may allow a remote attacker to execute arbitrary Perl code via a previously uploaded text file, potentially delivered via a traversal vector.
|
2013-05-02
|
YaBB Load.pl guestlanguage Cookie Text Attachment Arbitrary Perl Code Execution
|
|
37238
Description:
(Description Provided by CVE) : Directory traversal vulnerability in Yet another Bulletin Board (YaBB) 2.1 and earlier allows remote authenticated users to execute arbitrary Perl code via a .. (dot dot) in the userlanguage profile setting, which sets the userlanguage key of the member hash, and is propagated to the language variable in (1) HelpCentre.pl and (2) ICQPager.pl, (3) the use_lang variable in Subs.pl, and the actlang variable in (4) Post.pl and (5) InstantMessage.pl; as demonstrated by pointing userlanguage to the English folder, modifying English/HelpCentre.lng file to contain Perl statements, and then invoking the help action in YaBB.pl.
|
2007-06-19
|
YaBB Multiple Script userlanguage Traversal Local File Inclusion
|
|
38020
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerabilities in Yet Another Bulletin Board (YaBB) 1.5.0 allow remote attackers to execute arbitrary script as other users and possibly steal authentication information via cookies by injecting arbitrary HTML or script into (1) news_icon of news_template.php, and (2) threadid and subject of index.html
|
2003-01-05
|
YaBB news_template.php news_icon Parameter XSS
|
|
67634
Description:
Unknown / Incomplete
|
2010-02-08
|
YaBB Poll Section Answer Field Local File Disclosure
|
|
37237
Description:
(Description Provided by CVE) : CRLF injection vulnerability in Yet another Bulletin Board (YaBB) 2.1 allows remote attackers to obtain administrative access via requests to (1) register.pl or (2) profile.pl that write CRLF sequences to a .vars file. NOTE: this can be leveraged to execute arbitrary code.
|
2007-06-12
|
YaBB profile.pl CRLF Injection Privilege Escalation
|
|
37236
Description:
(Description Provided by CVE) : CRLF injection vulnerability in Yet another Bulletin Board (YaBB) 2.1 allows remote attackers to obtain administrative access via requests to (1) register.pl or (2) profile.pl that write CRLF sequences to a .vars file. NOTE: this can be leveraged to execute arbitrary code.
|
2007-06-12
|
YaBB register.pl CRLF Injection Privilege Escalation
|
|
9746
Description:
YaBB SE contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when accessing the 'Admin.php' script directly, which will cause the server to return an error page containing the installation path resulting in a loss of confidentiality.
|
2004-08-25
|
YaBB SE Admin.php Path Disclosure
|
|
53677
Description:
Unknown / Incomplete
|
2003-04-22
|
YaBB SE Change Profile language Parameter Remote File Inclusion
|
|
29146
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in index.php in Yet another Bulletin Board (YaBB) allows remote attackers to inject arbitrary web script or HTML via the categories parameter.
|
2006-08-10
|
YaBB SE index.php categories Parameter XSS
|
|
3971
Description:
YaBB SE contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'index.php' script not properly sanitizing user-supplied input to the 'quote' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2004-02-16
|
YaBB SE index.php quote Parameter SQL Injection
|
|
6733
Description:
(Description Provided by CVE) : Directory traversal vulnerability in ModifyMessage.php in YaBB SE 1.5.4 through 1.5.5b allows remote attackers to delete arbitrary files via a .. (dot dot) in the attachOld parameter.
|
2004-03-01
|
YaBB SE ModifyMessage.php Arbitrary File Deletion
|
|
6734
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in YaBB SE 1.5.4 through 1.5.5b allow remote attackers to execute arbitrary SQL via (1) the msg parameter in ModifyMessage.php or (2) the postid parameter in ModifyMessage.php.
|
2004-03-01
|
YaBB SE ModifyMessage.php Multiple Parameter SQL Injection
|
|
53674
Description:
Unknown / Incomplete
|
2003-01-24
|
YaBB SE News.php template Parameter Remote File Inclusion
|
|
53675
Description:
Unknown / Incomplete
|
2003-01-21
|
YaBB SE Packages.php sourcedir Parameter Remote File Inclusion
|
|
26783
Description:
YaBB SE contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'profile.php' script not properly sanitizing user-supplied input to the 'user' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2006-06-22
|
YaBB SE profile.php user Parameter SQL Injection
|
|
53676
Description:
YaBB SE contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'reminder.php' script not properly sanitizing user-supplied input to the 'user' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2003-01-10
|
YaBB SE reminder.php user Parameter SQL Injection
|