vendor:
YapBB
by:
cijfer
9.3
CVSS
HIGH
Remote Command Execution
78
CWE
Product Name: YapBB
Affected Version From: 1.2 Beta
Affected Version To: 1.2 Beta
Patch Exists: YES
Related CWE: N/A
CPE: a:yapbb:yapbb:1.2
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2006
YapBB <=1.2 Beta Remote Command Execution Exploit
This exploit allows an attacker to execute arbitrary commands on a vulnerable YapBB <=1.2 Beta system. The exploit works by sending a specially crafted HTTP request to the vulnerable system, which contains the command to be executed. The command is then executed on the vulnerable system and the output is returned to the attacker.
Mitigation:
Upgrade to the latest version of YapBB.