Show filters
119 Total Results
Displaying 71-80 of 119
Sort by:
Attacker Value
Unknown

CVE-2006-3758

Disclosure Date: July 21, 2006 (last updated October 04, 2023)
inc/init.php in Archive Mode (Light) in MyBB (aka MyBulletinBoard) 1.1.4 calls the extract function with EXTR_OVERWRITE on HTTP POST and GET variables, which allows remote attackers to overwrite arbitrary variables, as demonstrated via an SQL injection using the _SERVER[HTTP_CLIENT_IP] parameter in archive/index.php.
0
Attacker Value
Unknown

CVE-2006-3761

Disclosure Date: July 21, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in inc/functions_post.php in MyBB (aka MyBulletinBoard) 1.0 RC2 through 1.1.4 allows remote attackers to inject arbitrary web script or HTML via a javascript URI with an SGML numeric character reference in the url BBCode tag, as demonstrated using "javascript".
0
Attacker Value
Unknown

CVE-2006-3760

Disclosure Date: July 21, 2006 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in MyBB (aka MyBulletinBoard) 1.1.4 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown

CVE-2006-3420

Disclosure Date: July 07, 2006 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in editpost.php in MyBulletinBoard (MyBB) before 1.1.5 allows remote attackers to perform unauthorized actions as a logged in user and delete arbitrary forum posts via a bbcode IMG tag with a modified delete parameter in a deletepost action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2006-3243

Disclosure Date: June 27, 2006 (last updated October 04, 2023)
SQL injection vulnerability in usercp.php in MyBB (MyBulletinBoard) 1.0 through 1.1.3 allows remote attackers to execute arbitrary SQL commands via the showcodebuttons parameter.
0
Attacker Value
Unknown

CVE-2006-2908

Disclosure Date: June 13, 2006 (last updated October 04, 2023)
The domecode function in inc/functions_post.php in MyBulletinBoard (MyBB) 1.1.2, and possibly other versions, allows remote attackers to execute arbitrary PHP code via the username field, which is used in a preg_replace function call with a /e (executable) modifier.
0
Attacker Value
Unknown

CVE-2006-2949

Disclosure Date: June 12, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in private.php in MyBB 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the do parameter.
0
Attacker Value
Unknown

CVE-2006-2589

Disclosure Date: May 25, 2006 (last updated October 04, 2023)
SQL injection vulnerability in rss.php in MyBB (aka MyBulletinBoard) 1.1.1 allows remote attackers to execute arbitrary SQL commands via the comma parameter. NOTE: it is not clear from the original report how this attack can succeed, since the demonstration URL uses a variable that is overwritten with static data in the extracted source code.
0
Attacker Value
Unknown

CVE-2006-2336

Disclosure Date: May 12, 2006 (last updated October 04, 2023)
SQL injection vulnerability in showthread.php in MyBB (aka MyBulletinBoard) 1.1.1 allows remote attackers to execute arbitrary SQL commands via the comma parameter.
0
Attacker Value
Unknown

CVE-2006-2333

Disclosure Date: May 12, 2006 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in MyBB (aka MyBulletinBoard) 1.1.1 allow remote attackers to execute arbitrary SQL commands via the e-mail address when registering for a forum that requires e-mail verification, which is not properly handled in (1) usercp.php and (2) member.php.
0