Show filters
35 Total Results
Displaying 11-20 of 35
Sort by:
Attacker Value
Unknown
CVE-2009-3202
Disclosure Date: September 16, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in search.php in ULoKI PHP Forum 2.1 allows remote attackers to inject arbitrary web script or HTML via the term parameter.
0
Attacker Value
Unknown
CVE-2008-6890
Disclosure Date: August 03, 2009 (last updated October 04, 2023)
SQL injection vulnerability in messages.asp in ASP Forum Script allows remote attackers to execute arbitrary SQL commands via the message_id parameter.
0
Attacker Value
Unknown
CVE-2008-6891
Disclosure Date: August 03, 2009 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in ASP Forum Script allow remote attackers to inject arbitrary web script or HTML via the (1) forum_id parameter to (a) new_message.asp and (b) messages.asp, and the (2) query string to default.asp.
0
Attacker Value
Unknown
CVE-2008-6777
Disclosure Date: May 01, 2009 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in MyPHP Forum 3.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in a confirm action, the (2) user parameter in a newconfirm action, and (3) reqpwd action to member.php; and the (4) quote parameter in a post action and (5) pid parameter in an edit action to post.php, different vectors than CVE-2005-0413.2 and CVE-2007-6667.
0
Attacker Value
Unknown
CVE-2008-6527
Disclosure Date: March 25, 2009 (last updated October 04, 2023)
SQL injection vulnerability in forum.asp in GO4I.NET ASP Forum 1.0 allows remote attackers to execute arbitrary SQL commands via the iFor parameter.
0
Attacker Value
Unknown
CVE-2008-6147
Disclosure Date: February 16, 2009 (last updated October 04, 2023)
ForumApp 3.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for (1) data/8690.mdb or (2) data/8690BAK.mdb.
0
Attacker Value
Unknown
CVE-2008-0388
Disclosure Date: January 23, 2008 (last updated October 04, 2023)
SQL injection vulnerability in the WP-Forum 1.7.4 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the user parameter in a showprofile action to the default URI.
0
Attacker Value
Unknown
CVE-2008-0099
Disclosure Date: January 08, 2008 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in MyPHP Forum 3.0 and earlier allow remote attackers to execute arbitrary SQL commands via the searchtext parameter to search.php, and unspecified other vectors.
0
Attacker Value
Unknown
CVE-2007-6667
Disclosure Date: January 04, 2008 (last updated October 04, 2023)
SQL injection vulnerability in faq.php in MyPHP Forum 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: the member.php vector is already covered by CVE-2005-0413.
0
Attacker Value
Unknown
CVE-2007-5564
Disclosure Date: October 18, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in NSSboard (formerly Simple PHP Forum) 6.1 allow remote attackers to inject arbitrary web script or HTML via (1) HTML tags when BBcode is disabled; or the (2) user, (3) email, or (4) Real Name fields in a profile.
0