Show filters
95 Total Results
Displaying 61-70 of 95
Sort by:
Attacker Value
Unknown
CVE-2006-4585
Disclosure Date: September 06, 2006 (last updated October 04, 2023)
SQL injection vulnerability in admin/editer.php in Tr Forum 2.0 allows remote authenticated users to execute arbitrary SQL commands via the id2 parameter. NOTE: this can be leveraged with other Tr Forum vulnerabilities to allow unauthenticated attackers to gain privileges.
0
Attacker Value
Unknown
CVE-2006-4586
Disclosure Date: September 06, 2006 (last updated October 04, 2023)
The admin panel in Tr Forum 2.0 accepts a username and password hash for authentication, which allows remote authenticated users to perform unauthorized actions, as demonstrated by modifying user settings via the id parameter to /membres/modif_profil.php, and changing a password via /membres/change_mdp.php. NOTE: this can be leveraged with other Tr Forum vulnerabilities to allow unauthenticated attackers to gain privileges.
0
Attacker Value
Unknown
CVE-2006-2947
Disclosure Date: June 12, 2006 (last updated October 04, 2023)
Dmx Forum 2.1a allows remote attackers to obtain username and password information via a direct request to pops/edit.php with a modified membre parameter.
0
Attacker Value
Unknown
CVE-2006-0974
Disclosure Date: March 03, 2006 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in failure.asp in Battleaxe bttlxeForum 2.0 allows remote attackers to inject arbitrary web script or HTML via the err_txt parameter.
0
Attacker Value
Unknown
CVE-2006-0877
Disclosure Date: February 24, 2006 (last updated February 22, 2025)
Cross-site scripting vulnerability in Easy Forum 2.5 allows remote attackers to inject arbitrary web script or HTML via the image variable.
0
Attacker Value
Unknown
CVE-2006-0471
Disclosure Date: January 31, 2006 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in the bbcode function in functions.php in my little homepage my little forum, as last modified in June 2005, allows remote attackers to inject arbitrary Javascript via a javascript URI in BBcode link tags.
0
Attacker Value
Unknown
CVE-2005-4311
Disclosure Date: December 17, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in DCForum 6.25 and earlier, and possibly DCForum+ 1.x, allows remote attackers to inject arbitrary web script or HTML via (1) the page parameter in dcboard.php and (2) unspecified search parameters.
0
Attacker Value
Unknown
CVE-2005-4249
Disclosure Date: December 15, 2005 (last updated February 22, 2025)
ADP Forum 2.0 through 2.0.3 stores sensitive information in plaintext files under the web document root with insufficient access control, which allows remote attackers to obtain user credentials via requests to the forum/users directory.
0
Attacker Value
Unknown
CVE-2005-2781
Disclosure Date: September 02, 2005 (last updated February 22, 2025)
The Avatar upload feature in FUD Forum before 2.7.0 does not properly verify uploaded files, which allows remote attackers to execute arbitrary PHP code via a file with a .php extension that contains image data followed by PHP code.
0
Attacker Value
Unknown
CVE-2005-2600
Disclosure Date: August 17, 2005 (last updated February 22, 2025)
FUDForum 2.6.15 with "Tree View" enabled, as used in other products such as phpgroupware and egroupware, allows remote attackers to read private posts via a modified mid parameter.
0