CVE-2007-3208
Status: ModifiedHigh (10)—
CRLF injection vulnerability in Yet another Bulletin Board (YaBB) 2.1 allows remote attackers to obtain administrative access via requests to (1) register.pl or (2) profile.pl that write CRLF sequences to a .vars file. NOTE: this can be leveraged to execute arbitrary code.
CVSS
- Version: 2.0
- Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C
- Base score: 10
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 5.86%
- Percentile among all scored CVEs: 93
- Score date: 10/8/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- NVD-CWE-Other
References
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=538
- http://osvdb.org/37236
- http://osvdb.org/37237
- http://secunia.com/advisories/25656
- http://www.securityfocus.com/bid/24455
- http://www.securitytracker.com/id?1018236
- http://www.yabbforum.com/community/?board=general%3Baction=display%3Bnum=1181678785
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34848
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=538
- http://osvdb.org/37236
- http://osvdb.org/37237
- http://secunia.com/advisories/25656
- http://www.securityfocus.com/bid/24455
- http://www.securitytracker.com/id?1018236
- http://www.yabbforum.com/community/?board=general%3Baction=display%3Bnum=1181678785
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34848
Raw JSON (NVD)
Show
{
"id": "CVE-2007-3208",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 10,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": true,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2007-06-14T19:30:00.000",
"references": [
{
"url": "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=538",
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/37236",
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/37237",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/25656",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/24455",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securitytracker.com/id?1018236",
"source": "cve@mitre.org"
},
{
"url": "http://www.yabbforum.com/community/?board=general%3Baction=display%3Bnum=1181678785",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/34848",
"source": "cve@mitre.org"
},
{
"url": "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=538",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://osvdb.org/37236",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://osvdb.org/37237",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/25656",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/24455",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id?1018236",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.yabbforum.com/community/?board=general%3Baction=display%3Bnum=1181678785",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/34848",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "CRLF injection vulnerability in Yet another Bulletin Board (YaBB) 2.1 allows remote attackers to obtain administrative access via requests to (1) register.pl or (2) profile.pl that write CRLF sequences to a .vars file. NOTE: this can be leveraged to execute arbitrary code."
},
{
"lang": "es",
"value": "Vulnerabilidad de inyección CRLF en Yet another Bulletin Board (YaBB) 2.1 permite a atacantes remotos obtener acceso de administrador a través de respuestas en (1) register.pl o (2) profile.pl que escribe secuencias CRLF en un archivo .vars. NOTA: esto puede ser acoplado con ejecución de código arbitrario."
}
],
"lastModified": "2026-06-16T22:41:16.420",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:yabb:yabb:2.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9279B5DA-9534-43BB-BAEB-C3FFFE4CFA35"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}