Show filters
11 Total Results
Displaying 1-10 of 11
Sort by:
Attacker Value
Unknown

CVE-2018-15596

Disclosure Date: August 28, 2018 (last updated November 27, 2024)
An issue was discovered in inc/class_feedgeneration.php in MyBB 1.8.17. On the forum RSS Syndication page, one can generate a URL such as http://localhost/syndication.php?fid=&type=atom1.0&limit=15. The thread titles (within title elements of the generated XML documents) aren't sanitized, leading to XSS.
0
Attacker Value
Unknown

CVE-2018-10678

Disclosure Date: May 13, 2018 (last updated November 26, 2024)
MyBB 1.8.15, when accessed with Microsoft Edge, mishandles 'target="_blank" rel="noopener"' in A elements, which makes it easier for remote attackers to conduct redirection attacks.
0
Attacker Value
Unknown

CVE-2018-7305

Disclosure Date: February 21, 2018 (last updated November 26, 2024)
MyBB 1.8.14 is not checking for a valid CSRF token, leading to arbitrary deletion of user accounts.
0
Attacker Value
Unknown

CVE-2018-6844

Disclosure Date: February 08, 2018 (last updated November 26, 2024)
MyBB 1.8.14 has XSS via the Title or Description field on the Edit Forum screen.
0
Attacker Value
Unknown

CVE-2015-8974

Disclosure Date: January 31, 2017 (last updated November 25, 2024)
SQL injection vulnerability in the Group Promotions module in the admin control panel in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown

CVE-2015-8973

Disclosure Date: January 31, 2017 (last updated November 25, 2024)
xmlhttp.php in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allows remote attackers to bypass intended access restrictions via vectors related to the forum password.
0
Attacker Value
Unknown

CVE-2015-8975

Disclosure Date: January 31, 2017 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in the error handler in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 might allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2015-8977

Disclosure Date: January 31, 2017 (last updated November 25, 2024)
MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allow remote attackers to obtain the installation path via vectors involving error log files.
0
Attacker Value
Unknown

CVE-2015-8976

Disclosure Date: January 31, 2017 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 might allow remote attackers to inject arbitrary web script or HTML via vectors related to "old upgrade files."
0
Attacker Value
Unknown

CVE-2014-9241

Disclosure Date: December 03, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in MyBB (aka MyBulletinBoard) 1.8.x before 1.8.2 allow remote attackers to inject arbitrary web script or HTML via the (1) type parameter to report.php, (2) signature parameter in a do_editsig action to usercp.php, or (3) title parameter in the style-templates module in an edit_template action or (4) file parameter in the config-languages module in an edit action to admin/index.php.
0