Back

CVE-2004-2754

SQL injection vulnerability in SSI.php in YaBB SE 1.5.4, 1.5.3, and possibly other versions before 1.5.5 allows remote attackers to execute arbitrary SQL commands via the ID_MEMBER parameter to the (1) recentTopics and (2) welcome functions.

Published: Dec 31, 2004 Modified: Jun 16, 2026
CWE-89

CVSS Metrics

Affected Products (9)

Vendor Product Version
yabb yabb_se 0.8
yabb yabb_se 1.1.3
yabb yabb_se 1.4.1
yabb yabb_se 1.5.0
yabb yabb_se 1.5.1
yabb yabb_se 1.5.1_rc1
yabb yabb_se 1.5.2
yabb yabb_se 1.5.3
yabb yabb_se 1.5.4

GitHub Security Advisory GHSA-45hc-2hjf-p969

SQL injection vulnerability in SSI.php in YaBB SE 1.5.4, 1.5.3, and possibly other versions...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 2.35%

Top 18% most likely to be exploited

Threat Score 30.7 / 100

Data Sources

NVD EPSS GitHub