Back
CVE-2004-2403
Cross-site request forgery (CSRF) vulnerability in YaBB 1 GOLD SP 1.3.2 allows remote attackers to perform unauthorized actions as the administrative user via a link or IMG tag to YaBB.pl that specifies the desired action, id, and moda parameters.
Published: Dec 31, 2004
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (10)
| Vendor | Product | Version |
|---|---|---|
| yabb | yabb | 1.40 |
| yabb | yabb | 1.41 |
| yabb | yabb | 1_gold_-_sp_1 |
| yabb | yabb | 1_gold_-_sp_1.2 |
| yabb | yabb | 1_gold_-_sp_1.3 |
| yabb | yabb | 1_gold_-_sp_1.3.1 |
| yabb | yabb | 1_gold_-_sp_1.3.2 |
| yabb | yabb | 1_gold_release |
| yabb | yabb | 2000-09-01 |
| yabb | yabb | 2000-09-11 |
GitHub Security Advisory GHSA-cg5v-fvrh-4wvf
Cross-site request forgery (CSRF) vulnerability in YaBB 1 GOLD SP 1.3.2 allows remote attackers...
References (10)
- http://archives.neohapsis.com/archives/bugtraq/2004-09/0227.html Exploit
- http://secunia.com/advisories/12593 Exploit, Vendor Advisory
- http://www.osvdb.org/10243
- http://www.securityfocus.com/bid/11214 Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17453
- http://archives.neohapsis.com/archives/bugtraq/2004-09/0227.html Exploit
- http://secunia.com/advisories/12593 Exploit, Vendor Advisory
- http://www.osvdb.org/10243
- http://www.securityfocus.com/bid/11214 Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17453
Risk Scores
CVSS Score
10.0 / 10
EPSS Score
2.80%
Top 15% most likely to be exploited
Threat Score
40.8 / 100
Data Sources
NVD
EPSS
GitHub