Show filters
2 Total Results
Displaying 1-2 of 2
Sort by:
Attacker Value
Unknown
CVE-2020-17476
Disclosure Date: August 10, 2020 (last updated February 21, 2025)
Mibew Messenger before 3.2.7 allows XSS via a crafted user name.
0
Attacker Value
Unknown
CVE-2012-0829
Disclosure Date: February 14, 2012 (last updated October 04, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in Mibew Messenger 1.6.4 and earlier allow remote attackers to hijack the authentication of operators for requests that insert cross-site scripting (XSS) sequences via the (1) address or (2) threadid parameters to operator/ban.php; or (3) geolinkparams, (4) title, or (5) chattitle parameters to operator/settings.php.
0