Show filters
17 Total Results
Displaying 1-10 of 17
Sort by:
Attacker Value
Unknown

CVE-2008-0787

Disclosure Date: February 15, 2008 (last updated October 04, 2023)
SQL injection vulnerability in inc/datahandlers/pm.php in MyBB before 1.2.12 allows remote authenticated users to execute arbitrary SQL commands via the options[disablesmilies] parameter to private.php.
0
Attacker Value
Unknown

CVE-2006-3953

Disclosure Date: August 01, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in usercp.php in MyBB (aka MyBulletinBoard) 1.x allows remote attackers to inject arbitrary web script or HTML via the gallery parameter.
0
Attacker Value
Unknown

CVE-2006-3954

Disclosure Date: August 01, 2006 (last updated October 04, 2023)
Directory traversal vulnerability in usercp.php in MyBB (aka MyBulletinBoard) 1.x allows remote attackers to read arbitrary files via a .. (dot dot) in the gallery parameter in a (1) avatar or (2) do_avatar action.
0
Attacker Value
Unknown

CVE-2006-3761

Disclosure Date: July 21, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in inc/functions_post.php in MyBB (aka MyBulletinBoard) 1.0 RC2 through 1.1.4 allows remote attackers to inject arbitrary web script or HTML via a javascript URI with an SGML numeric character reference in the url BBCode tag, as demonstrated using "javascript".
0
Attacker Value
Unknown

CVE-2006-3243

Disclosure Date: June 27, 2006 (last updated October 04, 2023)
SQL injection vulnerability in usercp.php in MyBB (MyBulletinBoard) 1.0 through 1.1.3 allows remote attackers to execute arbitrary SQL commands via the showcodebuttons parameter.
0
Attacker Value
Unknown

CVE-2006-1974

Disclosure Date: April 21, 2006 (last updated October 04, 2023)
SQL injection vulnerability in index.php in MyBB (MyBulletinBoard) before 1.04 allows remote attackers to execute arbitrary SQL commands via the referrer parameter.
0
Attacker Value
Unknown

CVE-2006-1282

Disclosure Date: March 19, 2006 (last updated February 22, 2025)
CRLF injection vulnerability in inc/function.php in MyBulletinBoard (MyBB) 1.04 allows remote attackers to conduct cross-site scripting (XSS), poison caches, or hijack pages via CRLF (%0A%0D) sequences in the Referrer HTTP header field, possibly when redirecting to other web pages.
0
Attacker Value
Unknown

CVE-2006-1281

Disclosure Date: March 19, 2006 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in member.php in MyBulletinBoard (MyBB) 1.04 allows remote attackers to inject arbitrary web script or HTML via the url parameter, a different vulnerability than CVE-2006-1272. NOTE: 1.10 was later reported to be vulnerable.
0
Attacker Value
Unknown

CVE-2006-0770

Disclosure Date: February 18, 2006 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in calendar.php in MyBulletinBoard (MyBB) 1.0.4 allows remote attackers to inject arbitrary web script or HTML via a URL that is not sanitized before being returned as a link in "advanced details". NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2006-0523

Disclosure Date: February 02, 2006 (last updated February 22, 2025)
SQL injection vulnerability in global.php in MyBB before 1.03 allows remote attackers to execute arbitrary SQL commands via the templatelist variable.
0