First published: Fri Dec 31 2004(Updated: )
SQL injection vulnerability in SSI.php in YaBB SE 1.5.4, 1.5.3, and possibly other versions before 1.5.5 allows remote attackers to execute arbitrary SQL commands via the ID_MEMBER parameter to the (1) recentTopics and (2) welcome functions.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Yabb Yabb Se | =1.5.0 | |
Yabb Yabb Se | =1.1.3 | |
Yabb Yabb Se | =1.4.1 | |
Yabb Yabb Se | =1.5.1_rc1 | |
Yabb Yabb Se | =1.5.4 | |
Yabb Yabb Se | =0.8 | |
Yabb Yabb Se | =1.5.1 | |
Yabb Yabb Se | =1.5.2 | |
Yabb Yabb Se | =1.5.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-2754 has a moderate severity level due to the potential for remote SQL command execution.
To fix CVE-2004-2754, upgrade YaBB SE to version 1.5.5 or later.
CVE-2004-2754 affects YaBB SE versions 1.5.0, 1.5.1, 1.5.2, 1.5.3, 1.5.4, and earlier versions.
CVE-2004-2754 is an SQL injection vulnerability.
Yes, CVE-2004-2754 can be exploited remotely by attackers to execute arbitrary SQL commands.