CVE List

Id CVE No. Status Description Phase Votes Comments Actions
96232  CVE-2016-9412  Candidate  MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allow attackers to have unspecified impact via vectors related to low adminsid and sid entropy.  Assigned (20161117)  None (candidate not yet proposed)    View
96233  CVE-2016-9413  Candidate  The Admin control panel in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allows remote attackers to conduct clickjacking attacks via unspecified vectors.  Assigned (20161117)  None (candidate not yet proposed)    View
86250  CVE-2015-8973  Candidate  xmlhttp.php in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allows remote attackers to bypass intended access restrictions via vectors related to the forum password.  Assigned (20161117)  None (candidate not yet proposed)    View
96234  CVE-2016-9414  Candidate  MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allow remote attackers to obtain sensitive information by leveraging missing directory listing protection in upload directories.  Assigned (20161117)  None (candidate not yet proposed)    View
86251  CVE-2015-8974  Candidate  SQL injection vulnerability in the Group Promotions module in the admin control panel in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.  Assigned (20161117)  None (candidate not yet proposed)    View

Page 18640 of 20943, showing 5 records out of 104715 total, starting on record 93196, ending on 93200

Actions