Show filters
95 Total Results
Displaying 1-10 of 95
Sort by:
Attacker Value
Unknown

CVE-2024-7438

Disclosure Date: August 03, 2024 (last updated September 12, 2024)
A vulnerability has been found in SimpleMachines SMF 2.1.4 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /index.php?action=profile;u=2;area=showalerts;do=read of the component User Alert Read Status Handler. The manipulation of the argument aid leads to improper control of resource identifiers. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Attacker Value
Unknown

CVE-2024-7437

Disclosure Date: August 03, 2024 (last updated September 12, 2024)
A vulnerability, which was classified as critical, was found in SimpleMachines SMF 2.1.4. Affected is an unknown function of the file /index.php?action=profile;u=2;area=showalerts;do=remove of the component Delete User Handler. The manipulation of the argument aid leads to improper control of resource identifiers. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Attacker Value
Unknown

CVE-2023-3539

Disclosure Date: July 07, 2023 (last updated October 08, 2023)
A vulnerability, which was classified as problematic, has been found in SimplePHPscripts Simple Forum PHP 2.7. This issue affects some unknown processing of the file /preview.php of the component URL Parameter Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-233291.
Attacker Value
Unknown

CVE-2022-38935

Disclosure Date: February 15, 2023 (last updated October 08, 2023)
An issue was discovered in NiterForum version 2.5.0-beta in /src/main/java/cn/niter/forum/api/SsoApi.java and /src/main/java/cn/niter/forum/controller/AdminController.java, allows attackers to gain escalated privileges.
Attacker Value
Unknown

CVE-2017-20106

Disclosure Date: June 28, 2022 (last updated February 24, 2025)
A vulnerability, which was classified as critical, has been found in Lithium Forum 2017 Q1. This issue affects some unknown processing of the component Compose Message Handler. The manipulation of the argument upload_url leads to server-side request forgery. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.
Attacker Value
Unknown

CVE-2022-26173

Disclosure Date: June 16, 2022 (last updated February 23, 2025)
JForum v2.8.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via http://target_host:port/jforum-2.8.0/jforum.page, which allows attackers to arbitrarily add admin accounts.
Attacker Value
Unknown

CVE-2021-40509

Disclosure Date: September 04, 2021 (last updated February 23, 2025)
ViewCommon.java in JForum2 2.7.0 allows XSS via a user signature.
Attacker Value
Unknown

CVE-2013-7468

Disclosure Date: March 07, 2019 (last updated November 27, 2024)
Simple Machines Forum (SMF) 2.0.4 allows PHP Code Injection via the index.php?action=admin;area=languages;sa=editlang dictionary parameter.
0
Attacker Value
Unknown

CVE-2013-7467

Disclosure Date: March 07, 2019 (last updated November 27, 2024)
Simple Machines Forum (SMF) 2.0.4 allows XSS via the index.php?action=pm;sa=settings;save sa parameter.
0
Attacker Value
Unknown

CVE-2013-7466

Disclosure Date: March 07, 2019 (last updated November 27, 2024)
Simple Machines Forum (SMF) 2.0.4 allows local file inclusion, with resultant remote code execution, in install.php via ../ directory traversal in the db_type parameter if install.php remains present after installation.
0