First published: Fri Dec 31 2004(Updated: )
CRLF injection vulnerability in YaBB 1 Gold before 1.3.2 allows remote attackers to modify text file contents via the subject variable.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Yabb | =1_gold_-_sp_1.3 | |
Yabb | =1_gold_-_sp_1.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-2140 has a medium severity rating as it can lead to unauthorized file content modification.
To fix CVE-2004-2140, update YaBB to version 1.3.2 or later.
CVE-2004-2140 affects YaBB 1 Gold before version 1.3.2.
CVE-2004-2140 exploits a CRLF injection vulnerability through the subject variable.
Remote attackers can be impacted by CVE-2004-2140 as they can modify text file contents.