Show filters
18 Total Results
Displaying 11-18 of 18
Sort by:
Attacker Value
Unknown
CVE-2008-2019
Disclosure Date: April 30, 2008 (last updated October 04, 2023)
Simple Machines Forum (SMF), probably 1.1.4, relies on "randomly generated static" to hinder brute-force attacks on the WAV file (aka audio) CAPTCHA, which allows remote attackers to pass the CAPTCHA test via an automated attack that considers Hamming distances. NOTE: this issue reportedly exists because of an insufficient fix for CVE-2007-3308.
0
Attacker Value
Unknown
CVE-2008-0775
Disclosure Date: February 14, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in sboxDB.php in Simple Machines Forum (SMF) Shoutbox 1.14 through 1.16b allows remote attackers to inject arbitrary web script or HTML via strings to the shoutbox form that start with "&#", contain the desired script, and end with ";".
0
Attacker Value
Unknown
CVE-2008-0284
Disclosure Date: January 15, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Simple Machines Forum (SMF) 1.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) Itemid or (2) topic arguments.
0
Attacker Value
Unknown
CVE-2006-6375
Disclosure Date: December 07, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in display.php in Simple Machines Forum (SMF) 1.1 Final and earlier allows remote attackers to inject arbitrary web script or HTML via the contents of a file that is uploaded with the image parameter set, which can be interpreted as script by Internet Explorer's automatic type detection.
0
Attacker Value
Unknown
CVE-2006-4564
Disclosure Date: September 06, 2006 (last updated October 04, 2023)
SQL injection vulnerability in Sources/ManageBoards.php in Simple Machines Forum 1.1 RC3 allows remote attackers to execute arbitrary SQL commands via the cur_cat parameter.
0
Attacker Value
Unknown
CVE-2006-3773
Disclosure Date: July 24, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in smf.php in the SMF-Forum 1.3.1.3 Bridge Component (com_smf) For Joomla! and Mambo 4.5.3+ allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
0
Attacker Value
Unknown
CVE-2004-1996
Disclosure Date: May 05, 2004 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in Simple Machines Forum (SMF) 1.0 allows remote attackers to inject arbitrary web script via the size tag.
0
Attacker Value
Unknown
CVE-2004-1827
Disclosure Date: March 15, 2004 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in YaBB 1 Gold(SP1.3) and YaBB SE 1.5.1 Final allows remote attackers to inject arbitrary web script via the background:url property in (1) glow or (2) shadow tags.
0