Show filters
29 Total Results
Displaying 11-20 of 29
Sort by:
Attacker Value
Unknown
CVE-2008-2194
Disclosure Date: May 14, 2008 (last updated October 04, 2023)
SQL injection vulnerability in forums.php in DeluxeBB 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the sort parameter.
0
Attacker Value
Unknown
CVE-2008-0439
Disclosure Date: January 23, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in templates/default/admincp/attachments_header.php in DeluxeBB 1.1 allows remote attackers to inject arbitrary web script or HTML via the lang_listofmatches parameter.
0
Attacker Value
Unknown
CVE-2007-6237
Disclosure Date: December 04, 2007 (last updated October 04, 2023)
cp.php in DeluxeBB 1.09 does not verify that the membercookie parameter corresponds to the authenticated member during a profile update, which allows remote authenticated users to change the e-mail addresses of arbitrary accounts via a modified membercookie parameter, a different vector than CVE-2006-4078. NOTE: this can be leveraged for administrative access by requesting password-reset e-mail through a lostpw action to misc.php.
0
Attacker Value
Unknown
CVE-2006-5154
Disclosure Date: October 05, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in cp/sig.php in DeluxeBB 1.09 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the templatefolder parameter.
0
Attacker Value
Unknown
CVE-2006-4558
Disclosure Date: September 06, 2006 (last updated October 04, 2023)
DeluxeBB 1.06 and earlier, when run on the Apache HTTP Server with the mod_mime module, allows remote attackers to execute arbitrary PHP code by uploading files with double extensions via the fileupload parameter in a newthread action in newpost.php.
0
Attacker Value
Unknown
CVE-2006-4079
Disclosure Date: August 11, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in newpost.php in DeluxeBB 1.08, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the subject parameter (aka the topic title field).
0
Attacker Value
Unknown
CVE-2006-4080
Disclosure Date: August 11, 2006 (last updated October 04, 2023)
DeluxeBB 1.08, and possibly earlier, uses cookies that include the MD5 hash of a password, which allows remote attackers to gain privileges by sniffing or cross-site scripting (XSS) and conduct password guessing attacks.
0
Attacker Value
Unknown
CVE-2006-4078
Disclosure Date: August 11, 2006 (last updated October 04, 2023)
pm.php (aka the PM system) in DeluxeBB 1.08, and possibly earlier, allows remote attackers to bypass authentication by providing an arbitrary username in the membercookie cookie parameter.
0
Attacker Value
Unknown
CVE-2006-3795
Disclosure Date: July 24, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in DeluxeBB before 1.08 allow remote attackers to inject arbitrary web script or HTML via the (1) membercookie cookie in header.php and the (2) redirect parameter in misc.php.
0
Attacker Value
Unknown
CVE-2006-3799
Disclosure Date: July 24, 2006 (last updated October 04, 2023)
DeluxeBB 1.07 and earlier allows remote attackers to bypass SQL injection protection mechanisms via the login variable and certain other variables, by using lowercase "union select" or possibly other statements that do not match the uppercase "UNION SELECT."
0