AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2007-3208

HIGH · CVSS 10 EPSS 5.86%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2007-06-14 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2007-3208
Severity
HIGH
CVSS
10
EPSS
5.86%

Original NVD Description

CRLF injection vulnerability in Yet another Bulletin Board (YaBB) 2.1 allows remote attackers to obtain administrative access via requests to (1) register.pl or (2) profile.pl that write CRLF sequences to a .vars file. NOTE: this can be leveraged to execute arbitrary code.