Vulnerability index

Browse CVEs

128 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mybb MEDIUM 5.0
CVE-2007-0689

MyBB 1.2.4 allows remote attackers to obtain sensitive information via the (1) action[] parameter to member.php, (2) imagehash[] parameter to captcha…

Fix: after 1.2.4
Fix from $1,600 2007-05-14
Mybb HIGH 7.5
CVE-2007-2212

Multiple SQL injection vulnerabilities in calendar.php in MyBB (aka MyBulletinBoard) 1.2.5 and earlier allow remote attackers to execute arbitrary SQ…

Mitigation only
Fix from $1,950 2007-04-24
Mybb HIGH 7.5
CVE-2007-1963

SQL injection vulnerability in the create_session function in class_session.php in MyBB (aka MyBulletinBoard) 1.2.3 and earlier allows remote attacke…

Fix: after 1.2.3
Fix from $1,950 2007-04-11
Mybb MEDIUM 6.0
CVE-2007-1964

member.php in MyBB (aka MyBulletinBoard), when debug mode is available, allows remote authenticated users to change the password of any account by pr…

Mitigation only
Fix from $1,600 2007-04-11
Mybb MEDIUM 5.0
CVE-2007-0622

Cross-site request forgery (CSRF) vulnerability in MyBB (aka MyBulletinBoard) 1.2.2 allows remote attackers to send messages to arbitrary users. NOT…

Mitigation only
Fix from $1,600 2007-01-31
Mybb MEDIUM 6.0
CVE-2007-0544

Cross-site scripting (XSS) vulnerability in private.php in MyBB (aka MyBulletinBoard) allows remote authenticated users to inject arbitrary web scrip…

Mitigation only
Fix from $1,600 2007-01-29
Mybb HIGH 10.0
CVE-2006-0218

Multiple unspecified vulnerabilities in MyBulletinBoard (MyBB) before 1.0.2 have unspecified impact and attack vectors, related to (1) admin/moderate…

Fix: after 1.01
Fix from $1,950 2006-01-16
Mybb HIGH 7.5
CVE-2005-4199

Multiple SQL injection vulnerabilities in MyBulletinBoard (MyBB) before 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) mont…

Fix: after 1.0
Fix from $1,950 2005-12-13