CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
10392 | CVE-2004-1966 | Candidate | Multiple SQL injection vulnerabilities in Open Bulletin Board (OpenBB) 1.0.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) FID parameter in board.php, (2) sortorder, perpage, or id parameters in member.php, (3) forums parameter in search.php, or (4) PID or FID parameters in post.php. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10393 | CVE-2004-1967 | Candidate | Cross-site request forgery (CSRF) vulnerabilities in (1) cp_forums.php, (2) cp_usergroup.php, (3) cp_ipbans.php, (4) myhome.php, (5) post.php, or (6) moderator.php in Open Bulletin Board (OpenBB) 1.0.6 and earlier allow remote attackers to execute arbitrary code by including the code in an image tag or a link. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10394 | CVE-2004-1968 | Candidate | The readmsg action in myhome.php in Open Bulletin Board (OpenBB) 1.0.6 and earlier allows remote attackers to read arbitrary messages by modifying the id parameter. | Assigned (20050504) | None (candidate not yet proposed) | View | |
6043 | CVE-2002-1659 | Candidate | user_profile.asp in PortalApp 2.2 allows local users to gain privileges by modifying the user_id variable. | Assigned (20050504) | None (candidate not yet proposed) | View | |
10395 | CVE-2004-1969 | Candidate | The avatar upload capability in Open Bulletin Board (OpenBB) 1.0.6 and earlier allows remote attackers to execute arbitrary script by uploading files that include scripting code such as Javascript. | Assigned (20050504) | None (candidate not yet proposed) | View |
Page 19447 of 20943, showing 5 records out of 104715 total, starting on record 97231, ending on 97235