Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2007-3208
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2007-3208

Description:
CRLF injection vulnerability in Yet another Bulletin Board (YaBB) 2.1 allows remote attackers to obtain administrative access via requests to (1) register.pl or (2) profile.pl that write CRLF sequences to a .vars file. NOTE: this can be leveraged to execute arbitrary code.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/34848

ST
  1018236

SAID
  Secunia Advisory: SA25656

OSVDB
  37236
  37237

IDEFENSE
  http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=538

CONFIRM
  http://www.yabbforum.com/community/?board=general;action=display;num=1181678785

BID
  24455


Return to the previous page.