Show filters
138 Total Results
Displaying 71-80 of 138
Sort by:
Attacker Value
Unknown

CVE-2016-9408

Disclosure Date: January 31, 2017 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in the Mod control panel in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script or HTML via vectors involving editing users.
0
Attacker Value
Unknown

CVE-2016-9417

Disclosure Date: January 31, 2017 (last updated November 25, 2024)
The fetch_remote_file function in MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 allows remote attackers to conduct server-side request forgery (SSRF) attacks via unspecified vectors.
0
Attacker Value
Unknown

CVE-2015-8976

Disclosure Date: January 31, 2017 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 might allow remote attackers to inject arbitrary web script or HTML via vectors related to "old upgrade files."
0
Attacker Value
Unknown

CVE-2016-9419

Disclosure Date: January 31, 2017 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in the Admin control panel in MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2016-9415

Disclosure Date: January 31, 2017 (last updated November 25, 2024)
MyBB (aka MyBulletinBoard) before 1.8.8 on Windows and MyBB Merge System before 1.8.8 on Windows allow remote attackers to overwrite arbitrary CSS files via vectors related to "style import."
0
Attacker Value
Unknown

CVE-2016-9405

Disclosure Date: January 31, 2017 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in member validation in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2016-9404

Disclosure Date: January 31, 2017 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script or HTML via vectors related to login.
0
Attacker Value
Unknown

CVE-2015-4552

Disclosure Date: September 03, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the quick edit function in xmlhttp.php in MyBB (aka MyBulletinBoard) before 1.8.5 allows remote attackers to inject arbitrary web script or HTML via the content of a post.
0
Attacker Value
Unknown

CVE-2015-2786

Disclosure Date: March 29, 2015 (last updated October 05, 2023)
Unspecified vulnerability in MyBB (aka MyBulletinBoard) before 1.8.4 has unknown attack vectors related to "Group join request notifications sent to wrong group leaders."
0
Attacker Value
Unknown

CVE-2015-2352

Disclosure Date: March 19, 2015 (last updated October 05, 2023)
The cache handler in MyBB (aka MyBulletinBoard) before 1.8.4 does not properly check the encoding of input to the var_export function, which allows attackers to have an unspecified impact via unknown vectors.
0