Show filters
95 Total Results
Displaying 51-60 of 95
Sort by:
Attacker Value
Unknown
CVE-2007-3884
Disclosure Date: July 18, 2007 (last updated October 04, 2023)
SQL injection vulnerability in philboard_forum.asp in husrevforum 1.0.1 allows remote attackers to execute arbitrary SQL commands via the forumid parameter. NOTE: it was later reported that 2.0.1 is also affected.
0
Attacker Value
Unknown
CVE-2007-3539
Disclosure Date: July 03, 2007 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in QuickTicket 1.2 build:20070621 and QuickTalk Forum 1.3 allow remote attackers to execute arbitrary SQL commands via the (1) t and (2) f parameters in (a) qti_ind_post.php and (b) qti_ind_post_prt.php; (3) dir and (4) order parameters in qti_ind_member.php; (5) id parameter in qti_usr.php; and the (6) f parameter in qti_ind_topic.php. NOTE: it was later reported that vector 5 also affects 1.4, 1.5, and 1.5.0.3.
0
Attacker Value
Unknown
CVE-2007-3043
Disclosure Date: June 05, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Collaboration - File Sharing 01-20 up to 01-20-/B and 01-30 up to 01-30-/B in Hitachi Groupmax Collaboration Portal up to 07-30-/D, Groupmax Collaboration Web Client - Forum/File Sharing up to 07-30-/C, uCosminexus Collaboration Portal up to 06-30-/D, and uCosminexus Collaboration Portal - Forum/File Sharing up to 06-30-/C on Windows allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2007-1708
Disclosure Date: March 27, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in lib/db/ez_sql.php in ttCMS 4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the lib_path parameter.
0
Attacker Value
Unknown
CVE-2006-7153
Disclosure Date: March 07, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in index.php in MiniBB Forum 2 allows remote attackers to execute arbitrary code via a URL in the pathToFiles parameter.
0
Attacker Value
Unknown
CVE-2007-1131
Disclosure Date: February 27, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in sinapis.php in Sinapis Forum 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the fuss parameter.
0
Attacker Value
Unknown
CVE-2007-0642
Disclosure Date: January 31, 2007 (last updated October 04, 2023)
SQL injection vulnerability in tForum 2.00 in the Raymond BERTHOU script collection (aka RBL - ASP) allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) pass to user_confirm.asp.
0
Attacker Value
Unknown
CVE-2006-6891
Disclosure Date: December 31, 2006 (last updated October 04, 2023)
Vz (Adp) Forum 2.0.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the administrative account name and password hash via a direct request for users/admin.txt.
0
Attacker Value
Unknown
CVE-2006-5729
Disclosure Date: November 06, 2006 (last updated October 04, 2023)
Yazd Discussion Forum before 3.0 beta does not properly manage forum permissions, which allows remote authenticated users to (1) reply to a message in an arbitrary forum, if authorized to create a message in any forum; and (2) perform certain unauthorized forum actions, related to an "error in how the permissions were assembled" that assigns extra permissions to users.
0
Attacker Value
Unknown
CVE-2006-4584
Disclosure Date: September 06, 2006 (last updated October 04, 2023)
Tr Forum 2.0 allows remote attackers to bypass authentication and add an administrative account via the login and password parameters to admin/insert_admin.php.
0