Show filters
95 Total Results
Displaying 21-30 of 95
Sort by:
Attacker Value
Unknown

CVE-2014-5889

Disclosure Date: September 15, 2014 (last updated October 05, 2023)
The Android Forums (aka com.tapatalk.androidforumscom) application 2.4.4.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2013-7235

Disclosure Date: April 29, 2014 (last updated October 05, 2023)
Simple Machines Forum (SMF) before 1.1.19 and 2.x before 2.0.6 allows remote attackers to impersonate arbitrary users via multiple space characters characters.
0
Attacker Value
Unknown

CVE-2013-7236

Disclosure Date: April 29, 2014 (last updated October 05, 2023)
Simple Machines Forum (SMF) 2.0.6, 1.1.19, and earlier allows remote attackers to impersonate arbitrary users via a Unicode homoglyph character in a username.
0
Attacker Value
Unknown

CVE-2013-7234

Disclosure Date: April 29, 2014 (last updated October 05, 2023)
Simple Machines Forum (SMF) before 1.1.19 and 2.x before 2.0.6 allows remote attackers to conduct clickjacking attacks via an X-Frame-Options header.
0
Attacker Value
Unknown

CVE-2011-5277

Disclosure Date: April 08, 2014 (last updated October 05, 2023)
Multiple SQL injection vulnerabilities in signature.php in the Advanced Forum Signatures (aka afsignatures) plugin 2.0.4 for MyBB allow remote attackers to execute arbitrary SQL commands via the (1) afs_type, (2) afs_background, (3) afs_showonline, (4) afs_bar_left, (5) afs_bar_center, (6) afs_full_line1, (7) afs_full_line2, (8) afs_full_line3, (9) afs_full_line4, (10) afs_full_line5, or (11) afs_full_line6 parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2011-5278

Disclosure Date: April 08, 2014 (last updated October 05, 2023)
SQL injection vulnerability in signature.php in Advanced Forum Signatures plugin (aka afsignatures) 2.0.4 for MyBB allows remote attackers to execute arbitrary SQL commands via the afs_bar_right parameter.
0
Attacker Value
Unknown

CVE-2013-6936

Disclosure Date: December 04, 2013 (last updated October 05, 2023)
Multiple SQL injection vulnerabilities in ajaxfs.php in the Ajax forum stat (Ajaxfs) Plugin 2.0 for MyBB (aka MyBulletinBoard) allow remote attackers to execute arbitrary SQL commands via the (1) tooltip or (2) usertooltip parameter.
0
Attacker Value
Unknown

CVE-2013-4465

Disclosure Date: October 25, 2013 (last updated October 05, 2023)
Unrestricted file upload vulnerability in the avatar upload functionality in Simple Machines Forum before 2.0.6 and 2.1 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory.
0
Attacker Value
Unknown

CVE-2012-5338

Disclosure Date: September 23, 2013 (last updated October 05, 2023)
Open redirect vulnerability in JForum 2.1.9 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the returnPath parameter in a validateLogin action to jforum.page.
0
Attacker Value
Unknown

CVE-2013-5309

Disclosure Date: August 16, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in install/forum_data/src/custom_fields.inc.t in FUDforum 3.0.4.1 and earlier, when registering a new user, allows remote attackers to inject arbitrary web script or HTML via a custom profile field to index.php. NOTE: some of these details are obtained from third party information.
0