← Vulnerability feed

Vulnerability record · CVE-2004-2139 · published 31 December 2004

CVE-2004-2139: Yabb vulnerability

Yabb · Yabb

Unknown vulnerability in Adminedit.pl YaBB 1 Gold before 1.3.2 allows attackers to execute arbitrary code via settings.pl.

7.5 CVSS 2.0 High EPSS 2.1% · top 19.1%
7.5CVSS 2.0 base score
2.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References
16 Jun 2026Last modified by NVD

Description

Unknown vulnerability in Adminedit.pl YaBB 1 Gold before 1.3.2 allows attackers to execute arbitrary code via settings.pl.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2004-2139 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2007-3208Yabb vulnerabilityCRLF injection vulnerability in Yet another Bulletin Board (YaBB) 2.1 allows remote attackers to obtain administrative access via requests to (1) reg…EPSS 5.9%10.0CVE-2004-2403Yabb vulnerabilityCross-site request forgery (CSRF) vulnerability in YaBB 1 GOLD SP 1.3.2 allows remote attackers to perform unauthorized actions as the administrative…EPSS 2.8%10.0CVE-2004-0343Yabb vulnerabilityMultiple SQL injection vulnerabilities in YaBB SE 1.5.4 through 1.5.5b allow remote attackers to execute arbitrary SQL via (1) the msg parameter in M…EPSS 1.8%9.8CVE-2013-2057Yabb unrestricted file upload vulnerabilityYaBB through 2.5.2: 'guestlanguage' Cookie Parameter Local File Include VulnerabilityEPSS 2.1%7.5CVE-2006-3275Yabb vulnerabilitySQL injection vulnerability in profile.php in YaBB SE 1.5.5 and earlier allows remote attackers to execute SQL commands via a double-encoded user par…EPSS 1.2%7.5CVE-2002-0955Yabb vulnerabilityCross-site scripting vulnerability in YaBB.cgi for Yet Another Bulletin Board (YaBB) 1 Gold SP1 and earlier allows remote attackers to execute arbitr…EPSS 8.6%7.5CVE-2002-0117Yabb vulnerabilityCross-site scripting vulnerability in Yet Another Bulletin Board (YaBB) 1 Gold SP 1 and earlier allows remote attackers to execute arbitrary script a…EPSS 2.8%7.5CVE-2000-1176Yabb vulnerabilityDirectory traversal vulnerability in YaBB search.pl CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack in the "cats…EPSS 5.7%

Source: NIST National Vulnerability Database (record CVE-2004-2139), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.