Show filters
12 Total Results
Displaying 1-10 of 12
Sort by:
Attacker Value
Unknown
CVE-2008-4355
Disclosure Date: September 30, 2008 (last updated October 04, 2023)
SQL injection vulnerability in showprofil.php in Powie PSCRIPT Forum (aka PHP Forum or pForum) 1.30 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
0
Attacker Value
Unknown
CVE-2006-7063
Disclosure Date: February 24, 2007 (last updated October 04, 2023)
Directory traversal vulnerability in profile.php in TinyPHPforum 3.6 and earlier allows remote attackers to include and execute arbitrary files via ".." sequences in the uname parameter.
0
Attacker Value
Unknown
CVE-2006-6038
Disclosure Date: November 22, 2006 (last updated October 04, 2023)
SQL injection vulnerability in editpoll.php in Powie's PHP Forum (pForum) 1.29a and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
0
Attacker Value
Unknown
CVE-2006-1898
Disclosure Date: April 20, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Ralph Capper Tiny PHP Forum (TPF) 3.6 allow remote attackers to inject arbitrary web script or HTML via (1) the uname parameter in a view action in profile.php and (2) a login name. NOTE: the "Access to hash password" issue is already covered by CVE-2006-0103.
0
Attacker Value
Unknown
CVE-2006-0103
Disclosure Date: January 06, 2006 (last updated February 22, 2025)
TinyPHPForum 3.6 and earlier stores the (1) users/[USERNAME].hash and (2) users/[USERNAME].email files under the web root with insufficient access control, which allows remote attackers to list all registered users and possibly obtain other sensitive information.
0
Attacker Value
Unknown
CVE-2006-0102
Disclosure Date: January 06, 2006 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in TinyPHPForum (TPF) 3.6 and earlier allows remote attackers to inject arbitrary web script via a javascript: scheme in an "[a]" bbcode tag, possibly the txt parameter to action.php.
0
Attacker Value
Unknown
CVE-2006-0104
Disclosure Date: January 06, 2006 (last updated February 22, 2025)
Directory traversal vulnerability in TinyPHPForum 3.6 and earlier allows remote attackers to create a new user account, create a new topic, or view the profile of a user account, as demonstrated via a .. (dot dot) in the uname parameter to profile.php.
0
Attacker Value
Unknown
CVE-2005-4088
Disclosure Date: December 08, 2005 (last updated February 22, 2025)
SQL injection vulnerability in index.php in phpForumPro 2.2 allows remote attackers to execute arbitrary SQL commands via the (1) parent and (2) day parameters.
0
Attacker Value
Unknown
CVE-2004-1716
Disclosure Date: August 16, 2004 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in PForum before 1.26 allows remote attackers to inject arbitrary web script or HTML via the (1) IRC Server or (2) AIM ID fields in the user profile.
0
Attacker Value
Unknown
CVE-2003-0559
Disclosure Date: August 18, 2003 (last updated February 22, 2025)
mainfile.php in phpforum 2 RC-1, and possibly earlier versions, allows remote attackers to execute arbitrary PHP code by modifying the MAIN_PATH parameter to reference a URL on a remote web server that contains the code.
0