Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown

CVE-2019-12253

Disclosure Date: May 21, 2019 (last updated November 27, 2024)
my little forum before 2.4.20 allows CSRF to delete posts, as demonstrated by mode=posting&delete_posting.
0
Attacker Value
Unknown

CVE-2018-15569

Disclosure Date: August 20, 2018 (last updated February 15, 2024)
my little forum 2.4.12 allows CSRF for deletion of users.
0
Attacker Value
Unknown

CVE-2018-14936

Disclosure Date: August 05, 2018 (last updated February 15, 2024)
The Add page option in my little forum 2.4.12 allows XSS via the Title field.
0
Attacker Value
Unknown

CVE-2018-14937

Disclosure Date: August 05, 2018 (last updated February 15, 2024)
The Add page option in my little forum 2.4.12 allows XSS via the Menu Link field.
0
Attacker Value
Unknown

CVE-2015-1434

Disclosure Date: February 16, 2015 (last updated October 05, 2023)
Multiple SQL injection vulnerabilities in my little forum before 2.3.4 allow remote administrators to execute arbitrary SQL commands via the (1) letter parameter in a user action or (2) edit_category parameter to index.php.
0
Attacker Value
Unknown

CVE-2015-1435

Disclosure Date: February 16, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in my little forum before 2.3.4 allows remote attackers to inject arbitrary web script or HTML via the back parameter to index.php.
0
Attacker Value
Unknown

CVE-2015-1475

Disclosure Date: February 04, 2015 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in my little forum 2.3.3, 2.2, and 1.7 allow remote attackers to inject arbitrary web script or HTML via the (1) page or (2) category parameter to forum.php or the (3) page or (4) order parameter to (a) board_entry.php or (b) forum_entry.php.
0
Attacker Value
Unknown

CVE-2010-2133

Disclosure Date: June 02, 2010 (last updated October 04, 2023)
SQL injection vulnerability in contact.php in My Little Forum allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2007-2942.
0