Show filters
95 Total Results
Displaying 71-80 of 95
Sort by:
Attacker Value
Unknown

CVE-2005-1648

Disclosure Date: May 18, 2005 (last updated February 22, 2025)
Gurgens (GASoft) Ultimate Forum 1.0 stores the db/Genid.dat database file under the web document root with insufficient access control, which allows remote attackers to obtain and decrypt usernames and passwords.
0
Attacker Value
Unknown

CVE-2005-1584

Disclosure Date: May 14, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in index.php for Quick.Forum 2.1.6 allows remote attackers to inject arbitrary web script or HTML via the topic field in a NewTopic action.
0
Attacker Value
Unknown

CVE-2005-1570

Disclosure Date: May 14, 2005 (last updated February 22, 2025)
forum.asp in bttlxeForum 2.0 allows remote attackers to obtain full path information via a certain hex-encoded argument to the page parameter, possibly due to a SQL injection vulnerability.
0
Attacker Value
Unknown

CVE-2005-1586

Disclosure Date: May 14, 2005 (last updated February 22, 2025)
Quick.Forum 2.1.6 stores potentially sensitive information such as usernames, banned IP addresses, censored words, and backups under the web document root, which allows remote attackers to obtain that information via a direct request to (1) db/users.txt, (2) db/banList.txt, (3) db/censureWords.txt, or (4) backup files.
0
Attacker Value
Unknown

CVE-2005-1585

Disclosure Date: May 11, 2005 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in Quick.Forum 2.1.6 allow remote attackers to execute arbitrary SQL commands via the (1) iCategory or (2) page parameter to index.php, or (3) iCategory parameter in the query string to the forum directory.
0
Attacker Value
Unknown

CVE-2005-1404

Disclosure Date: May 03, 2005 (last updated February 22, 2025)
MyPHP Forum 1.0 allows remote attackers to spoof the username by modifying the (1) nbuser parameter to post.php or (2) sender parameter to privmsg.php.
0
Attacker Value
Unknown

CVE-2005-0413

Disclosure Date: April 27, 2005 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in MyPHP Forum 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the fid in forum.php, (2) the member parameter in member.php, (3) the email parameter in forgot.php, or (4) the nbuser or nbpass parameters in include.php. NOTE: it was later reported that vector 2 exists in 3.0 and earlier.
0
Attacker Value
Unknown

CVE-2004-2212

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
SQL injection vulnerability in forum.asp in AliveSites Forums 2.0 allows remote attackers to execute arbitrary SQL commands via the forum_id parameter.
0
Attacker Value
Unknown

CVE-2004-2211

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in AliveSites Forums 2.0 allows remote attackers to inject arbitrary web script or HTML via the (1) forum_id, (2) method, or (3) forum_title parameters to post.asp, (4) the forum_title parameter to forum.asp, or (5) the id parameter to post.asp.
0
Attacker Value
Unknown

CVE-2003-1458

Disclosure Date: December 31, 2003 (last updated February 22, 2025)
SQL injection vulnerability in Profile.php in ttCMS 2.2 and ttForum allows remote attackers to execute arbitrary SQL commands via the member name.
0