Show filters
95 Total Results
Displaying 11-20 of 95
Sort by:
Attacker Value
Unknown

CVE-2019-7550

Disclosure Date: February 12, 2019 (last updated November 27, 2024)
In JForum 2.1.8, an unauthenticated, remote attacker can enumerate whether a user exists by using the "create user" function. If a register/check/username?username= request corresponds to a username that exists, then an "is already in use" error is produced. NOTE: this product is discontinued.
0
Attacker Value
Unknown

CVE-2018-18075

Disclosure Date: October 09, 2018 (last updated November 27, 2024)
WikidForum 2.20 has SQL Injection via the rpc.php parent_post_id or num_records parameter, or the index.php?action=search select_sort parameter.
0
Attacker Value
Unknown

CVE-2018-15569

Disclosure Date: August 20, 2018 (last updated February 15, 2024)
my little forum 2.4.12 allows CSRF for deletion of users.
0
Attacker Value
Unknown

CVE-2018-14936

Disclosure Date: August 05, 2018 (last updated February 15, 2024)
The Add page option in my little forum 2.4.12 allows XSS via the Title field.
0
Attacker Value
Unknown

CVE-2018-14937

Disclosure Date: August 05, 2018 (last updated February 15, 2024)
The Add page option in my little forum 2.4.12 allows XSS via the Menu Link field.
0
Attacker Value
Unknown

CVE-2016-5727

Disclosure Date: February 09, 2017 (last updated November 26, 2024)
LogInOut.php in Simple Machines Forum (SMF) 2.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via vectors related to variables derived from user input in a foreach loop.
0
Attacker Value
Unknown

CVE-2016-5726

Disclosure Date: February 09, 2017 (last updated November 26, 2024)
Packages.php in Simple Machines Forum (SMF) 2.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via the themechanges array parameter.
0
Attacker Value
Unknown

CVE-2014-9261

Disclosure Date: March 23, 2015 (last updated October 05, 2023)
The sanitize function in Codoforum 2.5.1 does not properly implement filtering for directory traversal sequences, which allows remote attackers to read arbitrary files via a .. (dot dot) in the path parameter to index.php.
0
Attacker Value
Unknown

CVE-2015-1475

Disclosure Date: February 04, 2015 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in my little forum 2.3.3, 2.2, and 1.7 allow remote attackers to inject arbitrary web script or HTML via the (1) page or (2) category parameter to forum.php or the (3) page or (4) order parameter to (a) board_entry.php or (b) forum_entry.php.
0
Attacker Value
Unknown

CVE-2014-6642

Disclosure Date: September 22, 2014 (last updated October 05, 2023)
The Mark's Daily Apple Forum (aka com.tapatalk.marksdailyapplecomforum) application 2.4.9.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0