First published: Thu Mar 18 2004(Updated: )
Directory traversal vulnerability in ModifyMessage.php in YaBB SE 1.5.4 through 1.5.5b allows remote attackers to delete arbitrary files via a .. (dot dot) in the attachOld parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Yabb | =1.5.5 | |
Yabb | =1.5.5b |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0344 is considered a high severity vulnerability due to its potential for arbitrary file deletion.
To fix CVE-2004-0344, upgrade to YaBB SE version 1.5.6 or later where the vulnerability has been addressed.
CVE-2004-0344 affects YaBB SE versions 1.5.4 through 1.5.5b.
CVE-2004-0344 is a directory traversal vulnerability.
Yes, CVE-2004-0344 can be exploited remotely by attackers to delete files.