CVE-2004-2403
CRITICAL
10.0
CVSS Severity Score
Vulnerability Description
Cross-site request forgery (CSRF) vulnerability in YaBB 1 GOLD SP 1.3.2 allows remote attackers to perform unauthorized actions as the administrative user via a link or IMG tag to YaBB.pl that specifies the desired action, id, and moda parameters.
Affected Platforms (CPE)
📦
Yabb
Yabb
= 1.40📦
Yabb
Yabb
= 1.41📦
Yabb
Yabb
= 1_gold_-_sp_1📦
Yabb
Yabb
= 1_gold_-_sp_1.2📦
Yabb
Yabb
= 1_gold_-_sp_1.3📦
Yabb
Yabb
= 1_gold_-_sp_1.3.1📦
Yabb
Yabb
= 1_gold_-_sp_1.3.2📦
Yabb
Yabb
= 1_gold_release📦
Yabb
Yabb
= 2000-09-01📦
Yabb
