Show filters
247 Total Results
Displaying 211-220 of 247
Sort by:
Attacker Value
Unknown

CVE-2006-3828

Disclosure Date: July 25, 2006 (last updated October 04, 2023)
Incomplete blacklist vulnerability in Kailash Nadh boastMachine (formerly bMachine) 3.1 and earlier allows remote authenticated administrators to bypass SQL injection protection mechanisms by using commas, quote characters, pound sign (#) characters, "UNION," and "SELECT," which are not filtered by the product, which only checks for "insert," "delete," "update," and "replace."
0
Attacker Value
Unknown

CVE-2006-3829

Disclosure Date: July 25, 2006 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in bmc/admin.php in Kailash Nadh boastMachine (formerly bMachine) 3.1 and earlier allows remote attackers to perform unauthorized actions as an administrator and delete arbitrary user accounts via a delete_user action.
0
Attacker Value
Unknown

CVE-2006-2491

Disclosure Date: May 19, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in (1) index.php and (2) bmc/admin.php in BoastMachine (bMachine) 3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the query string, which is not properly filtered when it is accessed using the $_SERVER["PHP_SELF"] variable.
0
Attacker Value
Unknown

CVE-2006-1841

Disclosure Date: April 19, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in search.php in boastMachine (bMachine) 2.7, and possibly other versions before 2.9b, allows remote attackers to inject arbitrary web script or HTML via the key parameter, as used by the search field.
0
Attacker Value
Unknown

CVE-2006-0896

Disclosure Date: February 25, 2006 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in Sources/Register.php in Simple Machine Forum (SMF) 1.0.6 allows remote attackers to inject arbitrary web script or HTML via the X-Forwarded-For HTTP header field.
0
Attacker Value
Unknown

CVE-2006-0131

Disclosure Date: January 09, 2006 (last updated February 22, 2025)
boastMachine 3.1 allows remote attackers to obtain sensitive information via a direct request to (1) footer.php and (2) side_menu.php, which reveals the path in an error message.
0
Attacker Value
Unknown

CVE-2005-4159

Disclosure Date: December 11, 2005 (last updated February 22, 2025)
NOTE: this issue has been disputed by the vendor and third parties. SQL injection vulnerability in Memberlist.php in Simple Machines Forum (SMF) 1.1 rc1 and earlier allows remote attackers to execute arbitrary SQL commands via the start parameter. NOTE: the vendor says that since only one character can be modified, there is no SQL injection. Thus this might be an "invalid SQL syntax error." Multiple followups support the vendor
0
Attacker Value
Unknown

CVE-2005-2817

Disclosure Date: September 07, 2005 (last updated February 22, 2025)
Simple Machines Forum (SMF) 1-0-5 and earlier supports the use of URLs for avatar images, which allows remote attackers to monitor sensitive information of forum visitors such as IP address and user agent, as demonstrated using a PHP script on a malicious server.
0
Attacker Value
Unknown

CVE-2005-1772

Disclosure Date: May 31, 2005 (last updated February 22, 2025)
Buffer overflow in the client cd-key hash in Terminator 3: War of the Machines 1.16 and earlier allows remote attackers to cause a denial of service (application crash) via a long client cd-key hash value, a different vulnerability than CVE-2005-1556.
0
Attacker Value
Unknown

CVE-2005-1775

Disclosure Date: May 31, 2005 (last updated February 22, 2025)
Terminator 3: War of the Machines 1.16 and earlier allows remote attackers to cause a denial of service (application crash) via a large nickname.
0