Show filters
95 Total Results
Displaying 31-40 of 95
Sort by:
Attacker Value
Unknown
CVE-2013-3537
Disclosure Date: May 13, 2013 (last updated October 05, 2023)
Multiple SQL injection vulnerabilities in todooforum.php in Todoo Forum 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) id_post or (2) pg parameter.
0
Attacker Value
Unknown
CVE-2013-3538
Disclosure Date: May 13, 2013 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in todooforum.php in Todoo Forum 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) id_post or (2) pg parameter.
0
Attacker Value
Unknown
CVE-2012-5337
Disclosure Date: February 24, 2013 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in jforum.page in JForum 2.1.9 allow remote attackers to inject arbitrary web script or HTML via the (1) action, (2) match_type, (3) sort_by, or (4) start parameters.
0
Attacker Value
Unknown
CVE-2012-2099
Disclosure Date: January 24, 2013 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Wikidforum 2.10 allow remote attackers to inject arbitrary web script or HTML via the (1) search field, or the (2) Author or (3) select_sort parameters in an advanced search.
0
Attacker Value
Unknown
CVE-2012-6520
Disclosure Date: January 24, 2013 (last updated October 05, 2023)
Multiple SQL injection vulnerabilities in the advanced search in Wikidforum 2.10 allow remote attackers to execute arbitrary SQL commands via the (1) select_sort or (2) opt_search_select parameters. NOTE: this issue could not be reproduced by third parties.
0
Attacker Value
Unknown
CVE-2011-4569
Disclosure Date: November 29, 2011 (last updated October 04, 2023)
SQL injection vulnerability in userbarsettings.php in the Userbar plugin 2.2 for MyBB Forum allows remote attackers to execute arbitrary SQL commands via the image2 parameter.
0
Attacker Value
Unknown
CVE-2010-3931
Disclosure Date: January 20, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in multiple Rocomotion products, including P board 1.18 and other versions, P forum 1.30 and earlier, P up board 1.38 and other versions, P diary R 1.13 and earlier, P link 1.11 and earlier, P link compact 1.04 and earlier, pplog 3.31 and earlier, pplog2 3.37 and earlier, PM bbs 1.07 and earlier, PM up bbs 1.08 and earlier, and PM forum 1.18 and earlier, allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
0
Attacker Value
Unknown
CVE-2010-2133
Disclosure Date: June 02, 2010 (last updated October 04, 2023)
SQL injection vulnerability in contact.php in My Little Forum allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2007-2942.
0
Attacker Value
Unknown
CVE-2010-0938
Disclosure Date: March 08, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in todooforum.php in Todoo Forum 2.0 allows remote attackers to inject arbitrary web script or HTML via the id_forum parameter in a post action.
0
Attacker Value
Unknown
CVE-2010-0765
Disclosure Date: March 02, 2010 (last updated October 04, 2023)
fipsForum 2.6 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for _database/forumFips.mdb.
0