Show filters
14 Total Results
Displaying 1-10 of 14
Sort by:
Attacker Value
Unknown
CVE-2023-41538
Disclosure Date: August 30, 2023 (last updated February 25, 2025)
phpjabbers PHP Forum Script 3.0 is vulnerable to Cross Site Scripting (XSS) via the keyword parameter.
0
Attacker Value
Unknown
CVE-2023-3539
Disclosure Date: July 07, 2023 (last updated February 25, 2025)
A vulnerability, which was classified as problematic, has been found in SimplePHPscripts Simple Forum PHP 2.7. This issue affects some unknown processing of the file /preview.php of the component URL Parameter Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-233291.
0
Attacker Value
Unknown
CVE-2009-4677
Disclosure Date: March 08, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in search.php in phpFK PHP Forum ohne 7.0.4 allows remote attackers to inject arbitrary web script or HTML via the search parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2009-3202
Disclosure Date: September 16, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in search.php in ULoKI PHP Forum 2.1 allows remote attackers to inject arbitrary web script or HTML via the term parameter.
0
Attacker Value
Unknown
CVE-2008-6777
Disclosure Date: May 01, 2009 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in MyPHP Forum 3.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in a confirm action, the (2) user parameter in a newconfirm action, and (3) reqpwd action to member.php; and the (4) quote parameter in a post action and (5) pid parameter in an edit action to post.php, different vectors than CVE-2005-0413.2 and CVE-2007-6667.
0
Attacker Value
Unknown
CVE-2008-0099
Disclosure Date: January 08, 2008 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in MyPHP Forum 3.0 and earlier allow remote attackers to execute arbitrary SQL commands via the searchtext parameter to search.php, and unspecified other vectors.
0
Attacker Value
Unknown
CVE-2007-6667
Disclosure Date: January 04, 2008 (last updated October 04, 2023)
SQL injection vulnerability in faq.php in MyPHP Forum 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: the member.php vector is already covered by CVE-2005-0413.
0
Attacker Value
Unknown
CVE-2007-5564
Disclosure Date: October 18, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in NSSboard (formerly Simple PHP Forum) 6.1 allow remote attackers to inject arbitrary web script or HTML via (1) HTML tags when BBcode is disabled; or the (2) user, (3) email, or (4) Real Name fields in a profile.
0
Attacker Value
Unknown
CVE-2007-2182
Disclosure Date: April 24, 2007 (last updated October 04, 2023)
Unrestricted file upload vulnerability in forum_write.php in Maran PHP Forum allows remote attackers to upload and execute arbitrary PHP files via a trailing %00 in a filename in the page parameter.
0
Attacker Value
Unknown
CVE-2006-7088
Disclosure Date: March 02, 2007 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Simple PHP Forum before 0.4 allow remote attackers to execute arbitrary SQL commands via the username parameter to (1) logon_user.php and (2) update_profile.php.
0