Show filters
18 Total Results
Displaying 11-18 of 18
Sort by:
Attacker Value
Unknown
CVE-2023-3144
Disclosure Date: June 07, 2023 (last updated October 08, 2023)
A vulnerability classified as problematic was found in SourceCodester Online Discussion Forum Site 1.0. Affected by this vulnerability is an unknown functionality of the file admin\posts\manage_post.php. The manipulation of the argument title leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-231013 was assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2023-3143
Disclosure Date: June 07, 2023 (last updated October 08, 2023)
A vulnerability classified as problematic has been found in SourceCodester Online Discussion Forum Site 1.0. Affected is an unknown function of the file admin\posts\manage_post.php. The manipulation of the argument content leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-231012.
0
Attacker Value
Unknown
CVE-2022-31296
Disclosure Date: June 17, 2022 (last updated February 23, 2025)
Online Discussion Forum Site 1 was discovered to contain a blind SQL injection vulnerability via the component /odfs/posts/view_post.php.
0
Attacker Value
Unknown
CVE-2022-31295
Disclosure Date: June 16, 2022 (last updated February 23, 2025)
An issue in the delete_post() function of Online Discussion Forum Site 1 allows unauthenticated attackers to arbitrarily delete posts.
0
Attacker Value
Unknown
CVE-2022-31294
Disclosure Date: June 16, 2022 (last updated February 23, 2025)
An issue in the save_users() function of Online Discussion Forum Site 1 allows unauthenticated attackers to arbitrarily create or update user accounts.
0
Attacker Value
Unknown
CVE-2022-31913
Disclosure Date: June 16, 2022 (last updated February 23, 2025)
Online Discussion Forum Site v1.0 is vulnerable to Cross Site Scripting (XSS) via /odfs/classes/Master.php?f=save_category, name.
0
Attacker Value
Unknown
CVE-2022-31911
Disclosure Date: June 16, 2022 (last updated February 23, 2025)
Online Discussion Forum Site v1.0 is vulnerable to SQL Injection via /odfs/classes/Master.php?f=delete_team.
0
Attacker Value
Unknown
CVE-2020-28141
Disclosure Date: April 19, 2021 (last updated February 22, 2025)
The messaging subsystem in the Online Discussion Forum 1.0 is vulnerable to XSS in the message body. An authenticated user can send messages to arbitrary users on the system that include javascript that will execute when viewing the messages page.
0