CVE-2004-2403
CRITICAL
10.0
CVSS Severity Score
Vulnerability Description
Cross-site request forgery (CSRF) vulnerability in YaBB 1 GOLD SP 1.3.2 allows remote attackers to perform unauthorized actions as the administrative user via a link or IMG tag to YaBB.pl that specifies the desired action, id, and moda parameters.
Affected Platforms (CPE)
π¦
Yabb
Yabb
= 1.40π¦
Yabb
Yabb
= 1.41π¦
Yabb
Yabb
= 1_gold_-_sp_1π¦
Yabb
Yabb
= 1_gold_-_sp_1.2π¦
Yabb
Yabb
= 1_gold_-_sp_1.3π¦
Yabb
Yabb
= 1_gold_-_sp_1.3.1π¦
Yabb
Yabb
= 1_gold_-_sp_1.3.2π¦
Yabb
Yabb
= 1_gold_releaseπ¦
Yabb
Yabb
= 2000-09-01π¦
Yabb
