Show filters
12 Total Results
Displaying 1-10 of 12
Sort by:
Attacker Value
Unknown

CVE-2008-0787

Disclosure Date: February 15, 2008 (last updated October 04, 2023)
SQL injection vulnerability in inc/datahandlers/pm.php in MyBB before 1.2.12 allows remote authenticated users to execute arbitrary SQL commands via the options[disablesmilies] parameter to private.php.
0
Attacker Value
Unknown

CVE-2008-0382

Disclosure Date: January 22, 2008 (last updated October 04, 2023)
Multiple eval injection vulnerabilities in MyBB 1.2.10 and earlier allow remote attackers to execute arbitrary code via the sortby parameter to (1) forumdisplay.php or (2) a results action in search.php.
0
Attacker Value
Unknown

CVE-2006-4972

Disclosure Date: September 25, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in archive/index.php/forum-4.html in MyBB (aka MyBulletinBoard) allows remote attackers to inject arbitrary web script or HTML via the navbits[][name] parameter.
0
Attacker Value
Unknown

CVE-2006-4971

Disclosure Date: September 25, 2006 (last updated October 04, 2023)
MyBB (aka MyBulletinBoard) allows remote attackers to obtain sensitive information via a direct request for inc/plugins/hello.php, which reveals the path in an error message.
0
Attacker Value
Unknown

CVE-2006-3953

Disclosure Date: August 01, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in usercp.php in MyBB (aka MyBulletinBoard) 1.x allows remote attackers to inject arbitrary web script or HTML via the gallery parameter.
0
Attacker Value
Unknown

CVE-2006-3954

Disclosure Date: August 01, 2006 (last updated October 04, 2023)
Directory traversal vulnerability in usercp.php in MyBB (aka MyBulletinBoard) 1.x allows remote attackers to read arbitrary files via a .. (dot dot) in the gallery parameter in a (1) avatar or (2) do_avatar action.
0
Attacker Value
Unknown

CVE-2006-1912

Disclosure Date: April 20, 2006 (last updated October 04, 2023)
MyBB (MyBulletinBoard) 1.1.0 does not set the constant KILL_GLOBAL variable in (1) global.php and (2) inc/init.php, which allows remote attackers to initialize arbitrary variables that are processed by an @extract command, which could then be leveraged to conduct cross-site scripting (XSS) or SQL injection attacks.
0
Attacker Value
Unknown

CVE-2006-1717

Disclosure Date: April 11, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in newthread.php in MyBB (aka MyBulletinBoard) 1.10, when configured to permit new threads by unregistered users, allows remote attackers to inject arbitrary web script or HTML via the username.
0
Attacker Value
Unknown

CVE-2006-1716

Disclosure Date: April 11, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in inc/functions_post.php in MyBB (aka MyBulletinBoard) 1.10 allows remote attackers to inject arbitrary web script or HTML via a JavaScript event in a BBCode img tag. NOTE: the email vector is already covered by CVE-2006-1625, although it might stem from the same core issue.
0
Attacker Value
Unknown

CVE-2006-1625

Disclosure Date: April 05, 2006 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in inc/functions_post.php in MyBB (aka MyBulletinBoard) 1.10 allows remote attackers to inject arbitrary web script or HTML via a JavaScript event in a BBCode email tag, as demonstrated using the onmousemove event.
0