Show filters
247 Total Results
Displaying 211-220 of 247
Sort by:
Attacker Value
Unknown
CVE-2006-3828
Disclosure Date: July 25, 2006 (last updated October 04, 2023)
Incomplete blacklist vulnerability in Kailash Nadh boastMachine (formerly bMachine) 3.1 and earlier allows remote authenticated administrators to bypass SQL injection protection mechanisms by using commas, quote characters, pound sign (#) characters, "UNION," and "SELECT," which are not filtered by the product, which only checks for "insert," "delete," "update," and "replace."
0
Attacker Value
Unknown
CVE-2006-3829
Disclosure Date: July 25, 2006 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in bmc/admin.php in Kailash Nadh boastMachine (formerly bMachine) 3.1 and earlier allows remote attackers to perform unauthorized actions as an administrator and delete arbitrary user accounts via a delete_user action.
0
Attacker Value
Unknown
CVE-2006-2491
Disclosure Date: May 19, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in (1) index.php and (2) bmc/admin.php in BoastMachine (bMachine) 3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the query string, which is not properly filtered when it is accessed using the $_SERVER["PHP_SELF"] variable.
0
Attacker Value
Unknown
CVE-2006-1841
Disclosure Date: April 19, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in search.php in boastMachine (bMachine) 2.7, and possibly other versions before 2.9b, allows remote attackers to inject arbitrary web script or HTML via the key parameter, as used by the search field.
0
Attacker Value
Unknown
CVE-2006-0896
Disclosure Date: February 25, 2006 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in Sources/Register.php in Simple Machine Forum (SMF) 1.0.6 allows remote attackers to inject arbitrary web script or HTML via the X-Forwarded-For HTTP header field.
0
Attacker Value
Unknown
CVE-2006-0131
Disclosure Date: January 09, 2006 (last updated February 22, 2025)
boastMachine 3.1 allows remote attackers to obtain sensitive information via a direct request to (1) footer.php and (2) side_menu.php, which reveals the path in an error message.
0
Attacker Value
Unknown
CVE-2005-4159
Disclosure Date: December 11, 2005 (last updated February 22, 2025)
NOTE: this issue has been disputed by the vendor and third parties. SQL injection vulnerability in Memberlist.php in Simple Machines Forum (SMF) 1.1 rc1 and earlier allows remote attackers to execute arbitrary SQL commands via the start parameter. NOTE: the vendor says that since only one character can be modified, there is no SQL injection. Thus this might be an "invalid SQL syntax error." Multiple followups support the vendor
0
Attacker Value
Unknown
CVE-2005-2817
Disclosure Date: September 07, 2005 (last updated February 22, 2025)
Simple Machines Forum (SMF) 1-0-5 and earlier supports the use of URLs for avatar images, which allows remote attackers to monitor sensitive information of forum visitors such as IP address and user agent, as demonstrated using a PHP script on a malicious server.
0
Attacker Value
Unknown
CVE-2005-1772
Disclosure Date: May 31, 2005 (last updated February 22, 2025)
Buffer overflow in the client cd-key hash in Terminator 3: War of the Machines 1.16 and earlier allows remote attackers to cause a denial of service (application crash) via a long client cd-key hash value, a different vulnerability than CVE-2005-1556.
0
Attacker Value
Unknown
CVE-2005-1775
Disclosure Date: May 31, 2005 (last updated February 22, 2025)
Terminator 3: War of the Machines 1.16 and earlier allows remote attackers to cause a denial of service (application crash) via a large nickname.
0