Show filters
31 Total Results
Displaying 21-30 of 31
Sort by:
Attacker Value
Unknown

CVE-2018-15580

Disclosure Date: April 26, 2019 (last updated September 19, 2024)
Cross-Site Scripting (XSS) vulnerability in adm/contentformupdate.php in gnuboard5 before 5.3.1.6 allows remote attackers to inject arbitrary web script or HTML.
0
Attacker Value
Unknown

CVE-2018-15582

Disclosure Date: April 26, 2019 (last updated September 19, 2024)
Cross-Site Scripting (XSS) vulnerability in adm/sms_admin/num_book_write.php and adm/sms_admin/num_book_update.php in gnuboard5 before 5.3.1.6 allows remote attackers to inject arbitrary web script or HTML.
0
Attacker Value
Unknown

CVE-2018-15584

Disclosure Date: April 26, 2019 (last updated September 19, 2024)
Cross-Site Scripting (XSS) vulnerability in adm/boardgroup_form_update.php and adm/boardgroup_list_update.php in gnuboard5 before 5.3.1.6 allows remote attackers to inject arbitrary web script or HTML.
0
Attacker Value
Unknown

CVE-2018-15585

Disclosure Date: March 27, 2019 (last updated September 19, 2024)
Cross-Site Scripting (XSS) vulnerability in newwinform.php in GNUBOARD5 before 5.3.1.6 allows remote attackers to inject arbitrary web script or HTML via the popup title parameter.
0
Attacker Value
Unknown

CVE-2018-15583

Disclosure Date: March 25, 2019 (last updated September 19, 2024)
Cross-Site Scripting (XSS) vulnerability in point_list.php in GNUBOARD5 before 5.3.1.6 allows remote attackers to inject arbitrary web script or HTML via the popup title parameter.
Attacker Value
Unknown

CVE-2014-2339

Disclosure Date: March 19, 2014 (last updated October 05, 2023)
Multiple SQL injection vulnerabilities in bbs/ajax.autosave.php in GNUboard 5.x and possibly earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) subject or (2) content parameter.
0
Attacker Value
Unknown

CVE-2012-4873

Disclosure Date: September 06, 2012 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the file_download function in GNUBoard before 4.34.21 allows remote attackers to inject arbitrary web script or HTML via the filename parameter.
0
Attacker Value
Unknown

CVE-2011-4066

Disclosure Date: November 04, 2011 (last updated October 04, 2023)
SQL injection vulnerability in bbs/tb.php in Gnuboard 4.33.02 and earlier allows remote attackers to execute arbitrary SQL commands via the PATH_INFO.
0
Attacker Value
Unknown

CVE-2009-0290

Disclosure Date: January 27, 2009 (last updated October 04, 2023)
Directory traversal vulnerability in common.php in SIR GNUBoard 4.31.03 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the g4_path parameter. NOTE: in some environments, this can be leveraged for remote code execution via a data: URI or a UNC share pathname.
0
Attacker Value
Unknown

CVE-2005-0269

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
The file extension check in GNUBoard 3.40 and earlier only verifies extensions that contain all lowercase letters, which allows remote attackers to upload arbitrary files via file extensions that include uppercase letters.