Show filters
95 Total Results
Displaying 71-80 of 95
Sort by:
Attacker Value
Unknown
CVE-2005-1648
Disclosure Date: May 18, 2005 (last updated February 22, 2025)
Gurgens (GASoft) Ultimate Forum 1.0 stores the db/Genid.dat database file under the web document root with insufficient access control, which allows remote attackers to obtain and decrypt usernames and passwords.
0
Attacker Value
Unknown
CVE-2005-1584
Disclosure Date: May 14, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in index.php for Quick.Forum 2.1.6 allows remote attackers to inject arbitrary web script or HTML via the topic field in a NewTopic action.
0
Attacker Value
Unknown
CVE-2005-1570
Disclosure Date: May 14, 2005 (last updated February 22, 2025)
forum.asp in bttlxeForum 2.0 allows remote attackers to obtain full path information via a certain hex-encoded argument to the page parameter, possibly due to a SQL injection vulnerability.
0
Attacker Value
Unknown
CVE-2005-1586
Disclosure Date: May 14, 2005 (last updated February 22, 2025)
Quick.Forum 2.1.6 stores potentially sensitive information such as usernames, banned IP addresses, censored words, and backups under the web document root, which allows remote attackers to obtain that information via a direct request to (1) db/users.txt, (2) db/banList.txt, (3) db/censureWords.txt, or (4) backup files.
0
Attacker Value
Unknown
CVE-2005-1585
Disclosure Date: May 11, 2005 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in Quick.Forum 2.1.6 allow remote attackers to execute arbitrary SQL commands via the (1) iCategory or (2) page parameter to index.php, or (3) iCategory parameter in the query string to the forum directory.
0
Attacker Value
Unknown
CVE-2005-1404
Disclosure Date: May 03, 2005 (last updated February 22, 2025)
MyPHP Forum 1.0 allows remote attackers to spoof the username by modifying the (1) nbuser parameter to post.php or (2) sender parameter to privmsg.php.
0
Attacker Value
Unknown
CVE-2005-0413
Disclosure Date: April 27, 2005 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in MyPHP Forum 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the fid in forum.php, (2) the member parameter in member.php, (3) the email parameter in forgot.php, or (4) the nbuser or nbpass parameters in include.php. NOTE: it was later reported that vector 2 exists in 3.0 and earlier.
0
Attacker Value
Unknown
CVE-2004-2212
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
SQL injection vulnerability in forum.asp in AliveSites Forums 2.0 allows remote attackers to execute arbitrary SQL commands via the forum_id parameter.
0
Attacker Value
Unknown
CVE-2004-2211
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in AliveSites Forums 2.0 allows remote attackers to inject arbitrary web script or HTML via the (1) forum_id, (2) method, or (3) forum_title parameters to post.asp, (4) the forum_title parameter to forum.asp, or (5) the id parameter to post.asp.
0
Attacker Value
Unknown
CVE-2003-1458
Disclosure Date: December 31, 2003 (last updated February 22, 2025)
SQL injection vulnerability in Profile.php in ttCMS 2.2 and ttForum allows remote attackers to execute arbitrary SQL commands via the member name.
0