Show filters
16 Total Results
Displaying 1-10 of 16
Sort by:
Attacker Value
Unknown

CVE-2008-0787

Disclosure Date: February 15, 2008 (last updated October 04, 2023)
SQL injection vulnerability in inc/datahandlers/pm.php in MyBB before 1.2.12 allows remote authenticated users to execute arbitrary SQL commands via the options[disablesmilies] parameter to private.php.
0
Attacker Value
Unknown

CVE-2006-4972

Disclosure Date: September 25, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in archive/index.php/forum-4.html in MyBB (aka MyBulletinBoard) allows remote attackers to inject arbitrary web script or HTML via the navbits[][name] parameter.
0
Attacker Value
Unknown

CVE-2006-4971

Disclosure Date: September 25, 2006 (last updated October 04, 2023)
MyBB (aka MyBulletinBoard) allows remote attackers to obtain sensitive information via a direct request for inc/plugins/hello.php, which reveals the path in an error message.
0
Attacker Value
Unknown

CVE-2006-3953

Disclosure Date: August 01, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in usercp.php in MyBB (aka MyBulletinBoard) 1.x allows remote attackers to inject arbitrary web script or HTML via the gallery parameter.
0
Attacker Value
Unknown

CVE-2006-3954

Disclosure Date: August 01, 2006 (last updated October 04, 2023)
Directory traversal vulnerability in usercp.php in MyBB (aka MyBulletinBoard) 1.x allows remote attackers to read arbitrary files via a .. (dot dot) in the gallery parameter in a (1) avatar or (2) do_avatar action.
0
Attacker Value
Unknown

CVE-2006-3761

Disclosure Date: July 21, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in inc/functions_post.php in MyBB (aka MyBulletinBoard) 1.0 RC2 through 1.1.4 allows remote attackers to inject arbitrary web script or HTML via a javascript URI with an SGML numeric character reference in the url BBCode tag, as demonstrated using "javascript".
0
Attacker Value
Unknown

CVE-2006-3243

Disclosure Date: June 27, 2006 (last updated October 04, 2023)
SQL injection vulnerability in usercp.php in MyBB (MyBulletinBoard) 1.0 through 1.1.3 allows remote attackers to execute arbitrary SQL commands via the showcodebuttons parameter.
0
Attacker Value
Unknown

CVE-2006-1974

Disclosure Date: April 21, 2006 (last updated October 04, 2023)
SQL injection vulnerability in index.php in MyBB (MyBulletinBoard) before 1.04 allows remote attackers to execute arbitrary SQL commands via the referrer parameter.
0
Attacker Value
Unknown

CVE-2006-1282

Disclosure Date: March 19, 2006 (last updated February 22, 2025)
CRLF injection vulnerability in inc/function.php in MyBulletinBoard (MyBB) 1.04 allows remote attackers to conduct cross-site scripting (XSS), poison caches, or hijack pages via CRLF (%0A%0D) sequences in the Referrer HTTP header field, possibly when redirecting to other web pages.
0
Attacker Value
Unknown

CVE-2006-1281

Disclosure Date: March 19, 2006 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in member.php in MyBulletinBoard (MyBB) 1.04 allows remote attackers to inject arbitrary web script or HTML via the url parameter, a different vulnerability than CVE-2006-1272. NOTE: 1.10 was later reported to be vulnerable.
0