Show filters
247 Total Results
Displaying 71-80 of 247
Sort by:
Attacker Value
Unknown

CVE-2013-4395

Disclosure Date: February 12, 2020 (last updated February 21, 2025)
Simple Machines Forum (SMF) through 2.0.5 has XSS
Attacker Value
Unknown

CVE-2013-0192

Disclosure Date: February 07, 2020 (last updated February 21, 2025)
File Disclosure in SMF (SimpleMachines Forum) <= 2.0.3: Forum admin can read files such as the database config.
Attacker Value
Unknown

CVE-2009-5068

Disclosure Date: January 15, 2020 (last updated February 21, 2025)
There is a file disclosure vulnerability in SMF (Simple Machines Forum) affecting versions through v2.0.3. On some configurations a SMF deployment is shared by several "co-admins" that are not trusted beyond the SMF deployment. This vulnerability allows them to read arbitrary files on the filesystem and therefore gain new privileges by reading the settings.php with the database passwords.
Attacker Value
Unknown

CVE-2005-4891

Disclosure Date: January 15, 2020 (last updated February 21, 2025)
Simple Machine Forum (SMF) versions 1.0.4 and earlier have an SQL injection vulnerability that allows remote attackers to inject arbitrary SQL statements.
Attacker Value
Unknown

CVE-2019-6826

Disclosure Date: September 17, 2019 (last updated November 27, 2024)
A CWE-426: Untrusted Search Path vulnerability exists in SoMachine HVAC v2.4.1 and earlier versions, which could cause arbitrary code execution on the system running SoMachine HVAC when a malicious DLL library is loaded by the product.
Attacker Value
Unknown

CVE-2019-12490

Disclosure Date: September 11, 2019 (last updated November 27, 2024)
An issue was discovered in Simple Machines Forum (SMF) before 2.0.16. Reverse tabnabbing can occur because of use of _blank for external links.
Attacker Value
Unknown

CVE-2019-3570

Disclosure Date: July 18, 2019 (last updated November 27, 2024)
Call to the scrypt_enc() function in HHVM can lead to heap corruption by using specifically crafted parameters (N, r and p). This happens if the parameters are configurable by an attacker for instance by providing the output of scrypt_enc() in a context where Hack/PHP code would attempt to verify it by re-running scrypt_enc() with the same parameters. This could result in information disclosure, memory being overwriten or crashes of the HHVM process. This issue affects versions 4.3.0, 4.4.0, 4.5.0, 4.6.0, 4.7.0, 4.8.0, versions 3.30.5 and below, and all versions in the 4.0, 4.1, and 4.2 series.
Attacker Value
Unknown

CVE-2018-17388

Disclosure Date: June 19, 2019 (last updated November 27, 2024)
SQL Injection exists in Twilio WEB To Fax Machine System 1.0 via the email or password parameter to login_check.php, or the id parameter to add_email.php or edit_content.php.
0
Attacker Value
Unknown

CVE-2018-7823

Disclosure Date: May 22, 2019 (last updated November 27, 2024)
A Environment (CWE-2) vulnerability exists in SoMachine Basic, all versions, and Modicon M221(all references, all versions prior to firmware V1.10.0.0) which could cause remote launch of SoMachine Basic when sending crafted ethernet message.
Attacker Value
Unknown

CVE-2018-7821

Disclosure Date: May 22, 2019 (last updated November 27, 2024)
An Environment (CWE-2) vulnerability exists in SoMachine Basic, all versions, and Modicon M221(all references, all versions prior to firmware V1.10.0.0) which could cause cycle time impact when flooding the M221 ethernet interface while the Ethernet/IP adapter is activated.