3371Third-party advisory
http://securityreason.com/securityalert/3371 CVE-2004-2754
YABB SE 1.x - 'SSI.php' ID_MEMBER SQL Injection
Record summary
CVE-2004-2754 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
SQL injection vulnerability in SSI.php in YaBB SE 1.5.4, 1.5.3, and possibly other versions before 1.5.5 allows remote attackers to execute arbitrary SQL commands via the ID_MEMBER parameter to the (1) recentTopics and (2) welcome functions.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBYABB SE 1.x - 'SSI.php' ID_MEMBER SQL InjectionExploitDB exploitby BaCkSpAcENot analyzed1 file
References
8sourceforge.net
http://sourceforge.net/project/shownotes.php?release_id=210608&group_id=57105 3618vdb entry
http://www.osvdb.org/3618 20040119 Yabb SE SQL Injectionmailing list
http://www.securityfocus.com/archive/1/350244 9449vdb entry
http://www.securityfocus.com/bid/9449 1008764vdb entry
http://www.securitytracker.com/id?1008764 yabbse.org
http://www.yabbse.org/community/index.php?thread=27122 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2004-2754