CVE-2004-0343: SQL Injection
Published Mar 18, 2004
·Updated
Multiple SQL injection vulnerabilities in YaBB SE 1.5.4 through 1.5.5b allow remote attackers to execute arbitrary SQL via (1) the msg parameter in ModifyMessage.php or (2) the postid parameter in ModifyMessage.php.
Affected Software
3 affected components
Yabb Yabb=1.5.5
Yabb Yabb=1.5.5b
Yabb Yabb=1.5.4
Remediation
Patch Available
Event History
Mar 18, 2004
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0343?
CVE-2004-0343 is classified as a high severity vulnerability due to the potential for remote SQL injection attacks.
2
How do I fix CVE-2004-0343?
To fix CVE-2004-0343, upgrade YaBB SE to version 1.5.6 or a later version that addresses these SQL injection vulnerabilities.
3
What software is affected by CVE-2004-0343?
The affected software includes YaBB SE versions 1.5.4, 1.5.5, and 1.5.5b.
4
What types of attacks can be executed through CVE-2004-0343?
Through CVE-2004-0343, attackers can execute arbitrary SQL commands that may compromise the database.
5
Are there any known exploits for CVE-2004-0343?
Yes, there are known exploits that take advantage of the SQL injection vulnerabilities present in CVE-2004-0343.