Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
CRLF injection vulnerability in Yet another Bulletin Board (YaBB) 2.1 allows remote attackers to obtain administrative access via requests to (1) register.pl or (2) profile.pl that write CRLF sequences to a .vars file. NOTE: this can be leveraged to execute arbitrary code.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
YaBB论坛配置文件回车注入远程权限提升漏洞
Vulnerability Description
YaBB是用Perl编写的开源论坛系统。 YaBB在将某些配置文件表单字段写入到配置文件数据(.vars)文件之前没有正确地验证输入,允许攻击者通过注入特殊字符获得论坛管理员权限。 由于可以在注册期间执行攻击,因此未经认证的攻击者也可以在注册时通过register.pl脚本获得管理员权限。
CVSS Information
N/A
Vulnerability Type
N/A