Show filters
35 Total Results
Displaying 31-35 of 35
Sort by:
Attacker Value
Unknown

CVE-2005-1404

Disclosure Date: May 03, 2005 (last updated February 22, 2025)
MyPHP Forum 1.0 allows remote attackers to spoof the username by modifying the (1) nbuser parameter to post.php or (2) sender parameter to privmsg.php.
0
Attacker Value
Unknown

CVE-2005-0831

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
PHP-Post allows remote attackers to spoof the names of other users by registering with a username containing hex-encoded characters.
0
Attacker Value
Unknown

CVE-2005-0832

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in PHP-Post before 0.33 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
0
Attacker Value
Unknown

CVE-2005-0413

Disclosure Date: April 27, 2005 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in MyPHP Forum 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the fid in forum.php, (2) the member parameter in member.php, (3) the email parameter in forgot.php, or (4) the nbuser or nbpass parameters in include.php. NOTE: it was later reported that vector 2 exists in 3.0 and earlier.
0
Attacker Value
Unknown

CVE-2001-0972

Disclosure Date: August 31, 2001 (last updated February 22, 2025)
Surf-Net ASP Forum before 2.30 uses easily guessable cookies based on the UserID, which allows remote attackers to gain administrative privileges by calculating the value of the admin cookie (UserID 1), i.e. "0888888."
0