Show filters
14 Total Results
Displaying 1-10 of 14
Sort by:
Attacker Value
Unknown

CVE-2023-41538

Disclosure Date: August 30, 2023 (last updated February 25, 2025)
phpjabbers PHP Forum Script 3.0 is vulnerable to Cross Site Scripting (XSS) via the keyword parameter.
Attacker Value
Unknown

CVE-2023-3539

Disclosure Date: July 07, 2023 (last updated February 25, 2025)
A vulnerability, which was classified as problematic, has been found in SimplePHPscripts Simple Forum PHP 2.7. This issue affects some unknown processing of the file /preview.php of the component URL Parameter Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-233291.
Attacker Value
Unknown

CVE-2009-4677

Disclosure Date: March 08, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in search.php in phpFK PHP Forum ohne 7.0.4 allows remote attackers to inject arbitrary web script or HTML via the search parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2009-3202

Disclosure Date: September 16, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in search.php in ULoKI PHP Forum 2.1 allows remote attackers to inject arbitrary web script or HTML via the term parameter.
0
Attacker Value
Unknown

CVE-2008-6777

Disclosure Date: May 01, 2009 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in MyPHP Forum 3.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in a confirm action, the (2) user parameter in a newconfirm action, and (3) reqpwd action to member.php; and the (4) quote parameter in a post action and (5) pid parameter in an edit action to post.php, different vectors than CVE-2005-0413.2 and CVE-2007-6667.
0
Attacker Value
Unknown

CVE-2008-0099

Disclosure Date: January 08, 2008 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in MyPHP Forum 3.0 and earlier allow remote attackers to execute arbitrary SQL commands via the searchtext parameter to search.php, and unspecified other vectors.
0
Attacker Value
Unknown

CVE-2007-6667

Disclosure Date: January 04, 2008 (last updated October 04, 2023)
SQL injection vulnerability in faq.php in MyPHP Forum 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: the member.php vector is already covered by CVE-2005-0413.
0
Attacker Value
Unknown

CVE-2007-5564

Disclosure Date: October 18, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in NSSboard (formerly Simple PHP Forum) 6.1 allow remote attackers to inject arbitrary web script or HTML via (1) HTML tags when BBcode is disabled; or the (2) user, (3) email, or (4) Real Name fields in a profile.
0
Attacker Value
Unknown

CVE-2007-2182

Disclosure Date: April 24, 2007 (last updated October 04, 2023)
Unrestricted file upload vulnerability in forum_write.php in Maran PHP Forum allows remote attackers to upload and execute arbitrary PHP files via a trailing %00 in a filename in the page parameter.
0
Attacker Value
Unknown

CVE-2006-7088

Disclosure Date: March 02, 2007 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Simple PHP Forum before 0.4 allow remote attackers to execute arbitrary SQL commands via the username parameter to (1) logon_user.php and (2) update_profile.php.
0