Show filters
138 Total Results
Displaying 71-80 of 138
Sort by:
Attacker Value
Unknown
CVE-2016-9408
Disclosure Date: January 31, 2017 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in the Mod control panel in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script or HTML via vectors involving editing users.
0
Attacker Value
Unknown
CVE-2016-9417
Disclosure Date: January 31, 2017 (last updated November 25, 2024)
The fetch_remote_file function in MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 allows remote attackers to conduct server-side request forgery (SSRF) attacks via unspecified vectors.
0
Attacker Value
Unknown
CVE-2015-8976
Disclosure Date: January 31, 2017 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 might allow remote attackers to inject arbitrary web script or HTML via vectors related to "old upgrade files."
0
Attacker Value
Unknown
CVE-2016-9419
Disclosure Date: January 31, 2017 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in the Admin control panel in MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2016-9415
Disclosure Date: January 31, 2017 (last updated November 25, 2024)
MyBB (aka MyBulletinBoard) before 1.8.8 on Windows and MyBB Merge System before 1.8.8 on Windows allow remote attackers to overwrite arbitrary CSS files via vectors related to "style import."
0
Attacker Value
Unknown
CVE-2016-9405
Disclosure Date: January 31, 2017 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in member validation in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2016-9404
Disclosure Date: January 31, 2017 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script or HTML via vectors related to login.
0
Attacker Value
Unknown
CVE-2015-4552
Disclosure Date: September 03, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the quick edit function in xmlhttp.php in MyBB (aka MyBulletinBoard) before 1.8.5 allows remote attackers to inject arbitrary web script or HTML via the content of a post.
0
Attacker Value
Unknown
CVE-2015-2786
Disclosure Date: March 29, 2015 (last updated October 05, 2023)
Unspecified vulnerability in MyBB (aka MyBulletinBoard) before 1.8.4 has unknown attack vectors related to "Group join request notifications sent to wrong group leaders."
0
Attacker Value
Unknown
CVE-2015-2352
Disclosure Date: March 19, 2015 (last updated October 05, 2023)
The cache handler in MyBB (aka MyBulletinBoard) before 1.8.4 does not properly check the encoding of input to the var_export function, which allows attackers to have an unspecified impact via unknown vectors.
0