CVE

Id
8771  
CVE No.
CVE-2004-0343  
Status
Candidate  
Description
Multiple SQL injection vulnerabilities in YaBB SE 1.5.4 through 1.5.5b allow remote attackers to execute arbitrary SQL via (1) the msg parameter in ModifyMessage.php or (2) the postid parameter in ModifyMessage.php.  
Phase
Proposed (20040318)  
Votes
ACCEPT(3) Armstrong, Cole, Stracener | NOOP(3) Balinsky, Cox, Wall | REVIEWING(1) Green  
Comments