Show filters
14 Total Results
Displaying 1-10 of 14
Sort by:
Attacker Value
Unknown
CVE-2021-45822
Disclosure Date: March 16, 2022 (last updated February 23, 2025)
A cross-site scripting vulnerability is present in Xbtit 3.1. The stored XSS vulnerability occurs because /ajaxchat/sendChatData.php does not properly validate the value of the "n" (POST) parameter. Through this vulnerability, an attacker is capable to execute malicious JavaScript code.
0
Attacker Value
Unknown
CVE-2021-45821
Disclosure Date: March 16, 2022 (last updated February 23, 2025)
A blind SQL injection vulnerability exists in Xbtit 3.1 via the sid parameter in ajaxchat/getHistoryChatData.php file that is accessible by a registered user. As a result, a malicious user can extract sensitive data such as usernames and passwords and in some cases use this vulnerability in order to get a remote code execution on the remote web server.
0
Attacker Value
Unknown
CVE-2018-17870
Disclosure Date: October 01, 2018 (last updated November 27, 2024)
An issue was discovered in BTITeam XBTIT 2.5.4. The "returnto" parameter of account_change.php is vulnerable to an open redirect, a different vulnerability than CVE-2018-15683.
0
Attacker Value
Unknown
CVE-2018-15677
Disclosure Date: September 05, 2018 (last updated November 27, 2024)
The newsfeed (aka /index.php?page=viewnews) in BTITeam XBTIT 2.5.4 has stored XSS via the title of a news item. This is also exploitable via CSRF.
0
Attacker Value
Unknown
CVE-2018-15683
Disclosure Date: September 05, 2018 (last updated November 27, 2024)
An issue was discovered in BTITeam XBTIT. The "returnto" parameter of the login page is vulnerable to an open redirect due to a lack of validation. If a user is already logged in when accessing the page, they will be instantly redirected.
0
Attacker Value
Unknown
CVE-2018-15679
Disclosure Date: September 05, 2018 (last updated November 27, 2024)
An issue was discovered in BTITeam XBTIT 2.5.4. The "keywords" parameter in the search function available at /index.php?page=forums&action=search is vulnerable to reflected cross-site scripting.
0
Attacker Value
Unknown
CVE-2018-15678
Disclosure Date: September 05, 2018 (last updated November 27, 2024)
An issue was discovered in BTITeam XBTIT 2.5.4. The "act" parameter in the sign-up page available at /index.php?page=signup is vulnerable to reflected cross-site scripting.
0
Attacker Value
Unknown
CVE-2018-15682
Disclosure Date: September 05, 2018 (last updated November 27, 2024)
An issue was discovered in BTITeam XBTIT. Due to a lack of cross-site request forgery protection, it is possible to automate the action of sending private messages to users by luring an authenticated user to a web page that automatically submits a form on their behalf.
0
Attacker Value
Unknown
CVE-2018-16361
Disclosure Date: September 05, 2018 (last updated November 27, 2024)
An issue was discovered in BTITeam XBTIT 2.5.4. news.php allows XSS via the id parameter.
0
Attacker Value
Unknown
CVE-2018-15676
Disclosure Date: September 05, 2018 (last updated November 27, 2024)
An issue was discovered in BTITeam XBTIT. By using String.replace and eval, it is possible to bypass the includes/crk_protection.php anti-XSS mechanism that looks for a number of dangerous fingerprints.
0