First published: Thu Jun 14 2007(Updated: )
CRLF injection vulnerability in Yet another Bulletin Board (YaBB) 2.1 allows remote attackers to obtain administrative access via requests to (1) register.pl or (2) profile.pl that write CRLF sequences to a .vars file. NOTE: this can be leveraged to execute arbitrary code.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Yabb | =2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-3208 is classified as a high severity vulnerability due to its potential to allow remote attackers to gain administrative access.
To fix CVE-2007-3208, it is recommended to upgrade YaBB to a version that addresses this CRLF injection vulnerability.
CVE-2007-3208 affects users of YaBB 2.1, which is susceptible to CRLF injection issues.
Attackers exploiting CVE-2007-3208 can obtain administrative access and potentially execute arbitrary code on the vulnerable YaBB installation.
Yes, the exploitation of CVE-2007-3208 could lead to unauthorized changes or compromise of user data due to administrative access.