Show filters
247 Total Results
Displaying 191-200 of 247
Sort by:
Attacker Value
Unknown

CVE-2007-5943

Disclosure Date: November 14, 2007 (last updated October 04, 2023)
Simple Machines Forum (SMF) 1.1.4 allows remote attackers to read a message in private forums by using the advanced search module with the "show results as messages" option, then searching for possible keywords contained in that message.
0
Attacker Value
Unknown

CVE-2007-5646

Disclosure Date: October 23, 2007 (last updated October 04, 2023)
SQL injection vulnerability in Sources/Search.php in Simple Machines Forum (SMF) 1.1.3, when MySQL 5 is used, allows remote attackers to execute arbitrary SQL commands via the userspec parameter in a search2 action to index.php.
0
Attacker Value
Unknown

CVE-2007-5417

Disclosure Date: October 12, 2007 (last updated October 04, 2023)
Directory traversal vulnerability in index.php in boastMachine (aka bMachine) 2.8 allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter.
0
Attacker Value
Unknown

CVE-2007-5375

Disclosure Date: October 11, 2007 (last updated October 04, 2023)
Interpretation conflict in the Sun Java Virtual Machine (JVM) allows user-assisted remote attackers to conduct a multi-pin DNS rebinding attack and execute arbitrary JavaScript in an intranet context, when an intranet web server has an HTML document that references a "mayscript=true" Java applet through a local relative URI, which may be associated with different IP addresses by the browser and the JVM.
0
Attacker Value
Unknown

CVE-2007-3942

Disclosure Date: July 21, 2007 (last updated November 08, 2023)
Directory traversal vulnerability in index.php in Simple Machines Forum (SMF) 1.1.3 allows remote attackers to include local files via unspecified vectors related to the sourcedir parameter or the actionArray hash. NOTE: CVE and multiple third parties dispute this vulnerability because both sourcedir and actionArray are defined before use
0
Attacker Value
Unknown

CVE-2007-3702

Disclosure Date: July 11, 2007 (last updated October 04, 2023)
Directory traversal vulnerability in the load function in cgi-bin/mail/mailmachine.cgi in Mail Machine 3.989 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the archives parameter in a Load action.
0
Attacker Value
Unknown

CVE-2007-3308

Disclosure Date: June 21, 2007 (last updated October 04, 2023)
Simple Machines Forum (SMF) 1.1.2 uses a concatenation method with insufficient randomization when creating a WAV file CAPTCHA, which allows remote attackers to pass the CAPTCHA test via an automated brute-force attack.
0
Attacker Value
Unknown

CVE-2007-3309

Disclosure Date: June 21, 2007 (last updated October 04, 2023)
Unspecified vulnerability in Simple Machines Forum (SMF) 1.1.2 allows remote attackers to execute arbitrary PHP code during (1) creation or (2) editing of a message.
0
Attacker Value
Unknown

CVE-2007-2932

Disclosure Date: May 31, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in BoastMachine allows remote attackers to inject arbitrary web script or HTML via the blog parameter in a content search action.
0
Attacker Value
Unknown

CVE-2007-2860

Disclosure Date: May 24, 2007 (last updated October 04, 2023)
user.php in BoastMachine 3.0 platinum allows remote authenticated users to gain privileges via a modified id parameter, as demonstrated by an edit_post action.
0