CVE-2004-0291: SQL Injection
Published Mar 18, 2004
·Updated
SQL injection vulnerability in post.php for YaBB SE 1.5.4 and 1.5.5 allows remote attackers to obtain hashed passwords via the quote parameter.
Affected Software
2 affected components
Yabb Yabb=1.5.4
Yabb Yabb=1.5.5
Remediation
Patch Available
Event History
Mar 18, 2004
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0291?
CVE-2004-0291 is classified as a medium severity vulnerability due to its potential to expose hashed passwords.
2
How do I fix CVE-2004-0291?
The recommended fix for CVE-2004-0291 is to upgrade YaBB SE to version 1.5.6 or later, which addresses this vulnerability.
3
What software is affected by CVE-2004-0291?
CVE-2004-0291 affects YaBB SE versions 1.5.4 and 1.5.5.
4
What type of attack is associated with CVE-2004-0291?
CVE-2004-0291 is associated with SQL injection attacks that can lead to unauthorized access to hashed passwords.
5
Can CVE-2004-0291 be exploited remotely?
Yes, CVE-2004-0291 can be exploited remotely by attackers through specially crafted input.