Show filters
29 Total Results
Displaying 11-20 of 29
Sort by:
Attacker Value
Unknown

CVE-2008-2194

Disclosure Date: May 14, 2008 (last updated October 04, 2023)
SQL injection vulnerability in forums.php in DeluxeBB 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the sort parameter.
0
Attacker Value
Unknown

CVE-2008-0439

Disclosure Date: January 23, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in templates/default/admincp/attachments_header.php in DeluxeBB 1.1 allows remote attackers to inject arbitrary web script or HTML via the lang_listofmatches parameter.
0
Attacker Value
Unknown

CVE-2007-6237

Disclosure Date: December 04, 2007 (last updated October 04, 2023)
cp.php in DeluxeBB 1.09 does not verify that the membercookie parameter corresponds to the authenticated member during a profile update, which allows remote authenticated users to change the e-mail addresses of arbitrary accounts via a modified membercookie parameter, a different vector than CVE-2006-4078. NOTE: this can be leveraged for administrative access by requesting password-reset e-mail through a lostpw action to misc.php.
0
Attacker Value
Unknown

CVE-2006-5154

Disclosure Date: October 05, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in cp/sig.php in DeluxeBB 1.09 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the templatefolder parameter.
0
Attacker Value
Unknown

CVE-2006-4558

Disclosure Date: September 06, 2006 (last updated October 04, 2023)
DeluxeBB 1.06 and earlier, when run on the Apache HTTP Server with the mod_mime module, allows remote attackers to execute arbitrary PHP code by uploading files with double extensions via the fileupload parameter in a newthread action in newpost.php.
0
Attacker Value
Unknown

CVE-2006-4079

Disclosure Date: August 11, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in newpost.php in DeluxeBB 1.08, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the subject parameter (aka the topic title field).
0
Attacker Value
Unknown

CVE-2006-4080

Disclosure Date: August 11, 2006 (last updated October 04, 2023)
DeluxeBB 1.08, and possibly earlier, uses cookies that include the MD5 hash of a password, which allows remote attackers to gain privileges by sniffing or cross-site scripting (XSS) and conduct password guessing attacks.
0
Attacker Value
Unknown

CVE-2006-4078

Disclosure Date: August 11, 2006 (last updated October 04, 2023)
pm.php (aka the PM system) in DeluxeBB 1.08, and possibly earlier, allows remote attackers to bypass authentication by providing an arbitrary username in the membercookie cookie parameter.
0
Attacker Value
Unknown

CVE-2006-3795

Disclosure Date: July 24, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in DeluxeBB before 1.08 allow remote attackers to inject arbitrary web script or HTML via the (1) membercookie cookie in header.php and the (2) redirect parameter in misc.php.
0
Attacker Value
Unknown

CVE-2006-3799

Disclosure Date: July 24, 2006 (last updated October 04, 2023)
DeluxeBB 1.07 and earlier allows remote attackers to bypass SQL injection protection mechanisms via the login variable and certain other variables, by using lowercase "union select" or possibly other statements that do not match the uppercase "UNION SELECT."
0