Show filters
31 Total Results
Displaying 21-30 of 31
Sort by:
Attacker Value
Unknown
CVE-2018-15580
Disclosure Date: April 26, 2019 (last updated September 19, 2024)
Cross-Site Scripting (XSS) vulnerability in adm/contentformupdate.php in gnuboard5 before 5.3.1.6 allows remote attackers to inject arbitrary web script or HTML.
0
Attacker Value
Unknown
CVE-2018-15582
Disclosure Date: April 26, 2019 (last updated September 19, 2024)
Cross-Site Scripting (XSS) vulnerability in adm/sms_admin/num_book_write.php and adm/sms_admin/num_book_update.php in gnuboard5 before 5.3.1.6 allows remote attackers to inject arbitrary web script or HTML.
0
Attacker Value
Unknown
CVE-2018-15584
Disclosure Date: April 26, 2019 (last updated September 19, 2024)
Cross-Site Scripting (XSS) vulnerability in adm/boardgroup_form_update.php and adm/boardgroup_list_update.php in gnuboard5 before 5.3.1.6 allows remote attackers to inject arbitrary web script or HTML.
0
Attacker Value
Unknown
CVE-2018-15585
Disclosure Date: March 27, 2019 (last updated September 19, 2024)
Cross-Site Scripting (XSS) vulnerability in newwinform.php in GNUBOARD5 before 5.3.1.6 allows remote attackers to inject arbitrary web script or HTML via the popup title parameter.
0
Attacker Value
Unknown
CVE-2018-15583
Disclosure Date: March 25, 2019 (last updated September 19, 2024)
Cross-Site Scripting (XSS) vulnerability in point_list.php in GNUBOARD5 before 5.3.1.6 allows remote attackers to inject arbitrary web script or HTML via the popup title parameter.
0
Attacker Value
Unknown
CVE-2014-2339
Disclosure Date: March 19, 2014 (last updated October 05, 2023)
Multiple SQL injection vulnerabilities in bbs/ajax.autosave.php in GNUboard 5.x and possibly earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) subject or (2) content parameter.
0
Attacker Value
Unknown
CVE-2012-4873
Disclosure Date: September 06, 2012 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the file_download function in GNUBoard before 4.34.21 allows remote attackers to inject arbitrary web script or HTML via the filename parameter.
0
Attacker Value
Unknown
CVE-2011-4066
Disclosure Date: November 04, 2011 (last updated October 04, 2023)
SQL injection vulnerability in bbs/tb.php in Gnuboard 4.33.02 and earlier allows remote attackers to execute arbitrary SQL commands via the PATH_INFO.
0
Attacker Value
Unknown
CVE-2009-0290
Disclosure Date: January 27, 2009 (last updated October 04, 2023)
Directory traversal vulnerability in common.php in SIR GNUBoard 4.31.03 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the g4_path parameter. NOTE: in some environments, this can be leveraged for remote code execution via a data: URI or a UNC share pathname.
0
Attacker Value
Unknown
CVE-2005-0269
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
The file extension check in GNUBoard 3.40 and earlier only verifies extensions that contain all lowercase letters, which allows remote attackers to upload arbitrary files via file extensions that include uppercase letters.
0