First published: Mon May 03 2004(Updated: )
Post.pl in YaBB 1 Gold SP 1.2 allows remote attackers to modify records in the board's .txt file via carriage return characters in the subject field.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
YaBB | =1_gold_-_sp_1 | |
YaBB | =1_gold_-_sp_1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1982 has a medium severity rating due to its ability to allow remote attackers to alter records.
To fix CVE-2004-1982, ensure proper input validation to prevent carriage return characters from being processed in the subject field.
CVE-2004-1982 affects YaBB version 1 Gold SP 1 and 1 Gold SP 1.2.
The potential impacts of CVE-2004-1982 include unauthorized modification of board records which may lead to data integrity issues.
CVE-2004-1982 can be exploited by remote attackers who can manipulate the subject field of a post.