Vulnerability index

Browse CVEs

14 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Xbtit MEDIUM 6.1
CVE-2021-45822

A cross-site scripting vulnerability is present in Xbtit 3.1. The stored XSS vulnerability occurs because /ajaxchat/sendChatData.php does not properl…

No fix yet
Fix from $1,600 2022-03-16
Xbtit HIGH 8.8
CVE-2021-45821

A blind SQL injection vulnerability exists in Xbtit 3.1 via the sid parameter in ajaxchat/getHistoryChatData.php file that is accessible by a registe…

No fix yet
Fix from $1,950 2022-03-16
Xbtit MEDIUM 6.1
CVE-2018-17870

An issue was discovered in BTITeam XBTIT 2.5.4. The "returnto" parameter of account_change.php is vulnerable to an open redirect, a different vulnera…

Patch available
Fix from $1,600 2018-10-01
Xbtit MEDIUM 6.1
CVE-2018-16361

An issue was discovered in BTITeam XBTIT 2.5.4. news.php allows XSS via the id parameter.

Patch available
Fix from $1,600 2018-09-05
Xbtit MEDIUM 5.3
CVE-2018-15684

An issue was discovered in BTITeam XBTIT. PHP error logs are stored in an open directory (/include/logs) using predictable file names, which can lead…

Fix: after 2.5.4
Fix from $1,600 2018-09-05
Xbtit CRITICAL 9.8
CVE-2018-15680

An issue was discovered in BTITeam XBTIT 2.5.4. The hashed passwords stored in the xbtit_users table are stored as unsalted MD5 hashes, which makes i…

No fix yet
Fix from $2,300 2018-09-05
Xbtit CRITICAL 9.8
CVE-2018-15681

An issue was discovered in BTITeam XBTIT 2.5.4. When a user logs in, their password hash is rehashed using a predictable salt and stored in the "pass…

No fix yet
Fix from $2,300 2018-09-05
Xbtit HIGH 8.8
CVE-2018-15682

An issue was discovered in BTITeam XBTIT. Due to a lack of cross-site request forgery protection, it is possible to automate the action of sending pr…

Fix: after 2.5.4
Fix from $1,950 2018-09-05
Xbtit MEDIUM 6.1
CVE-2018-15677

The newsfeed (aka /index.php?page=viewnews) in BTITeam XBTIT 2.5.4 has stored XSS via the title of a news item. This is also exploitable via CSRF.

Patch available
Fix from $1,600 2018-09-05
Xbtit MEDIUM 6.1
CVE-2018-15678

An issue was discovered in BTITeam XBTIT 2.5.4. The "act" parameter in the sign-up page available at /index.php?page=signup is vulnerable to reflecte…

Patch available
Fix from $1,600 2018-09-05
Xbtit MEDIUM 6.1
CVE-2018-15679

An issue was discovered in BTITeam XBTIT 2.5.4. The "keywords" parameter in the search function available at /index.php?page=forums&action=search is …

Patch available
Fix from $1,600 2018-09-05
Xbtit MEDIUM 6.1
CVE-2018-15683

An issue was discovered in BTITeam XBTIT. The "returnto" parameter of the login page is vulnerable to an open redirect due to a lack of validation. I…

Fix: after 2.5.4
Fix from $1,600 2018-09-05
Xbtit MEDIUM 5.3
CVE-2018-15676

An issue was discovered in BTITeam XBTIT. By using String.replace and eval, it is possible to bypass the includes/crk_protection.php anti-XSS mechani…

Fix: after 2.5.4
Fix from $1,600 2018-09-05
Btitracker HIGH 7.5
CVE-2007-5986

SQL injection vulnerability in include/functions.php in BtiTracker before 1.4.5 allows remote attackers to execute arbitrary SQL commands via unspeci…

Fix: after 1.4.4
Fix from $1,950 2007-11-15