Show filters
60 Total Results
Displaying 11-20 of 60
Sort by:
Attacker Value
Unknown

CVE-2006-4449

Disclosure Date: August 30, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in attachment.php in MyBulletinBoard (MyBB) 1.1.7 and possibly other versions allows remote attackers to inject arbitrary web script or HTML via a GIF image that contains URL-encoded Javascript, which is rendered by Internet Explorer.
0
Attacker Value
Unknown

CVE-2006-3953

Disclosure Date: August 01, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in usercp.php in MyBB (aka MyBulletinBoard) 1.x allows remote attackers to inject arbitrary web script or HTML via the gallery parameter.
0
Attacker Value
Unknown

CVE-2006-3954

Disclosure Date: August 01, 2006 (last updated October 04, 2023)
Directory traversal vulnerability in usercp.php in MyBB (aka MyBulletinBoard) 1.x allows remote attackers to read arbitrary files via a .. (dot dot) in the gallery parameter in a (1) avatar or (2) do_avatar action.
0
Attacker Value
Unknown

CVE-2006-3775

Disclosure Date: July 24, 2006 (last updated October 04, 2023)
SQL injection vulnerability in the init function in class_session.php in MyBB (aka MyBulletinBoard) 1.1.5 allows remote attackers to execute arbitrary SQL commands via the CLIENT-IP HTTP header ($_SERVER['HTTP_CLIENT_IP'] variable), as utilized by index.php.
0
Attacker Value
Unknown

CVE-2006-3759

Disclosure Date: July 21, 2006 (last updated October 04, 2023)
Unspecified vulnerability in MyBB (aka MyBulletinBoard) 1.1.4, related has unspecified impact and attack vectors related to "user group manipulation."
0
Attacker Value
Unknown

CVE-2006-3758

Disclosure Date: July 21, 2006 (last updated October 04, 2023)
inc/init.php in Archive Mode (Light) in MyBB (aka MyBulletinBoard) 1.1.4 calls the extract function with EXTR_OVERWRITE on HTTP POST and GET variables, which allows remote attackers to overwrite arbitrary variables, as demonstrated via an SQL injection using the _SERVER[HTTP_CLIENT_IP] parameter in archive/index.php.
0
Attacker Value
Unknown

CVE-2006-3761

Disclosure Date: July 21, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in inc/functions_post.php in MyBB (aka MyBulletinBoard) 1.0 RC2 through 1.1.4 allows remote attackers to inject arbitrary web script or HTML via a javascript URI with an SGML numeric character reference in the url BBCode tag, as demonstrated using "javascript".
0
Attacker Value
Unknown

CVE-2006-3760

Disclosure Date: July 21, 2006 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in MyBB (aka MyBulletinBoard) 1.1.4 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown

CVE-2006-3420

Disclosure Date: July 07, 2006 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in editpost.php in MyBulletinBoard (MyBB) before 1.1.5 allows remote attackers to perform unauthorized actions as a logged in user and delete arbitrary forum posts via a bbcode IMG tag with a modified delete parameter in a deletepost action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2006-3243

Disclosure Date: June 27, 2006 (last updated October 04, 2023)
SQL injection vulnerability in usercp.php in MyBB (MyBulletinBoard) 1.0 through 1.1.3 allows remote attackers to execute arbitrary SQL commands via the showcodebuttons parameter.
0