CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10395  CVE-2004-1969  Candidate  The avatar upload capability in Open Bulletin Board (OpenBB) 1.0.6 and earlier allows remote attackers to execute arbitrary script by uploading files that include scripting code such as Javascript.  Assigned (20050504)  None (candidate not yet proposed)    View
10394  CVE-2004-1968  Candidate  The readmsg action in myhome.php in Open Bulletin Board (OpenBB) 1.0.6 and earlier allows remote attackers to read arbitrary messages by modifying the id parameter.  Assigned (20050504)  None (candidate not yet proposed)    View
10393  CVE-2004-1967  Candidate  Cross-site request forgery (CSRF) vulnerabilities in (1) cp_forums.php, (2) cp_usergroup.php, (3) cp_ipbans.php, (4) myhome.php, (5) post.php, or (6) moderator.php in Open Bulletin Board (OpenBB) 1.0.6 and earlier allow remote attackers to execute arbitrary code by including the code in an image tag or a link.  Assigned (20050504)  None (candidate not yet proposed)    View
10392  CVE-2004-1966  Candidate  Multiple SQL injection vulnerabilities in Open Bulletin Board (OpenBB) 1.0.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) FID parameter in board.php, (2) sortorder, perpage, or id parameters in member.php, (3) forums parameter in search.php, or (4) PID or FID parameters in post.php.  Assigned (20050504)  None (candidate not yet proposed)    View
10391  CVE-2004-1965  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Open Bulletin Board (OpenBB) 1.0.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) redirect parameter to member.php, (2) to parameter to myhome.php (3) TID parameter to post.php, or (4) redirect parameter to index.php.  Assigned (20050504)  None (candidate not yet proposed)    View

Page 18865 of 20943, showing 5 records out of 104715 total, starting on record 94321, ending on 94325

Actions