CVE-2004-2140: CRLF Injection
Published Dec 31, 2004
·Updated
CRLF injection vulnerability in YaBB 1 Gold before 1.3.2 allows remote attackers to modify text file contents via the subject variable.
Affected Software
2 affected components
Yabb Yabb=1_gold_-_sp_1.3
Yabb Yabb=1_gold_-_sp_1.3.1
Remediation
Patch Available
Event History
Dec 31, 2004
CVE Published
05:00 AM
Jun 30, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-2140?
CVE-2004-2140 has a medium severity rating as it can lead to unauthorized file content modification.
2
How do I fix CVE-2004-2140?
To fix CVE-2004-2140, update YaBB to version 1.3.2 or later.
3
Which versions of YaBB are affected by CVE-2004-2140?
CVE-2004-2140 affects YaBB 1 Gold before version 1.3.2.
4
What does CVE-2004-2140 exploit?
CVE-2004-2140 exploits a CRLF injection vulnerability through the subject variable.
5
Who can be impacted by CVE-2004-2140?
Remote attackers can be impacted by CVE-2004-2140 as they can modify text file contents.