Show filters
95 Total Results
Displaying 51-60 of 95
Sort by:
Attacker Value
Unknown

CVE-2007-3884

Disclosure Date: July 18, 2007 (last updated October 04, 2023)
SQL injection vulnerability in philboard_forum.asp in husrevforum 1.0.1 allows remote attackers to execute arbitrary SQL commands via the forumid parameter. NOTE: it was later reported that 2.0.1 is also affected.
0
Attacker Value
Unknown

CVE-2007-3539

Disclosure Date: July 03, 2007 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in QuickTicket 1.2 build:20070621 and QuickTalk Forum 1.3 allow remote attackers to execute arbitrary SQL commands via the (1) t and (2) f parameters in (a) qti_ind_post.php and (b) qti_ind_post_prt.php; (3) dir and (4) order parameters in qti_ind_member.php; (5) id parameter in qti_usr.php; and the (6) f parameter in qti_ind_topic.php. NOTE: it was later reported that vector 5 also affects 1.4, 1.5, and 1.5.0.3.
0
Attacker Value
Unknown

CVE-2007-3043

Disclosure Date: June 05, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Collaboration - File Sharing 01-20 up to 01-20-/B and 01-30 up to 01-30-/B in Hitachi Groupmax Collaboration Portal up to 07-30-/D, Groupmax Collaboration Web Client - Forum/File Sharing up to 07-30-/C, uCosminexus Collaboration Portal up to 06-30-/D, and uCosminexus Collaboration Portal - Forum/File Sharing up to 06-30-/C on Windows allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2007-1708

Disclosure Date: March 27, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in lib/db/ez_sql.php in ttCMS 4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the lib_path parameter.
0
Attacker Value
Unknown

CVE-2006-7153

Disclosure Date: March 07, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in index.php in MiniBB Forum 2 allows remote attackers to execute arbitrary code via a URL in the pathToFiles parameter.
0
Attacker Value
Unknown

CVE-2007-1131

Disclosure Date: February 27, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in sinapis.php in Sinapis Forum 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the fuss parameter.
0
Attacker Value
Unknown

CVE-2007-0642

Disclosure Date: January 31, 2007 (last updated October 04, 2023)
SQL injection vulnerability in tForum 2.00 in the Raymond BERTHOU script collection (aka RBL - ASP) allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) pass to user_confirm.asp.
0
Attacker Value
Unknown

CVE-2006-6891

Disclosure Date: December 31, 2006 (last updated October 04, 2023)
Vz (Adp) Forum 2.0.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the administrative account name and password hash via a direct request for users/admin.txt.
0
Attacker Value
Unknown

CVE-2006-5729

Disclosure Date: November 06, 2006 (last updated October 04, 2023)
Yazd Discussion Forum before 3.0 beta does not properly manage forum permissions, which allows remote authenticated users to (1) reply to a message in an arbitrary forum, if authorized to create a message in any forum; and (2) perform certain unauthorized forum actions, related to an "error in how the permissions were assembled" that assigns extra permissions to users.
0
Attacker Value
Unknown

CVE-2006-4584

Disclosure Date: September 06, 2006 (last updated October 04, 2023)
Tr Forum 2.0 allows remote attackers to bypass authentication and add an administrative account via the login and password parameters to admin/insert_admin.php.
0