Vulnerability index

Browse CVEs

41 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mybulletinboard HIGH 7.5
CVE-2009-2230

SQL injection vulnerability in inc/datahandlers/user.php in MyBB (aka MyBulletinBoard) before 1.4.7 allows remote authenticated users to execute arbi…

Fix: after 1.4.6
Fix from $1,950 2009-06-26
Mybulletinboard MEDIUM 6.5
CVE-2008-0787

SQL injection vulnerability in inc/datahandlers/pm.php in MyBB before 1.2.12 allows remote authenticated users to execute arbitrary SQL commands via …

Patch available
Fix from $1,600 2008-02-15
Mybulletinboard HIGH 7.5
CVE-2008-0382EPSS 42%

Multiple eval injection vulnerabilities in MyBB 1.2.10 and earlier allow remote attackers to execute arbitrary code via the sortby parameter to (1) f…

No fix yet
Fix from $1,950 2008-01-22
Mybulletinboard HIGH 7.5
CVE-2007-2211

SQL injection vulnerability in calendar.php in MyBB (aka MyBulletinBoard) 1.2.5 and earlier allows remote attackers to execute arbitrary SQL commands…

Fix: after 1.2.5
Fix from $1,950 2007-04-24
Mybulletinboard MEDIUM 5.1
CVE-2006-4972

Cross-site scripting (XSS) vulnerability in archive/index.php/forum-4.html in MyBB (aka MyBulletinBoard) allows remote attackers to inject arbitrary …

Mitigation only
Fix from $1,600 2006-09-25
Mybulletinboard MEDIUM 5.0
CVE-2006-4971

MyBB (aka MyBulletinBoard) allows remote attackers to obtain sensitive information via a direct request for inc/plugins/hello.php, which reveals the …

Mitigation only
Fix from $1,600 2006-09-25
Mybulletinboard MEDIUM 6.8
CVE-2006-4706

Cross-site scripting (XSS) vulnerability in inc/functions_post.php in MyBB (aka MyBulletinBoard) 1.1.7 allows remote attackers to inject arbitrary we…

Patch available
Fix from $1,600 2006-09-12
Mybulletinboard MEDIUM 6.8
CVE-2006-4707

Cross-site scripting (XSS) vulnerability in admin/global.php (aka the Admin CP login form) in MyBB (aka MyBulletinBoard) 1.1.7 allows remote attacker…

Patch available
Fix from $1,600 2006-09-12
Mybulletinboard MEDIUM 5.1
CVE-2006-4449

Cross-site scripting (XSS) vulnerability in attachment.php in MyBulletinBoard (MyBB) 1.1.7 and possibly other versions allows remote attackers to inj…

Patch available
Fix from $1,600 2006-08-30
Mybulletinboard MEDIUM 5.0
CVE-2006-3954

Directory traversal vulnerability in usercp.php in MyBB (aka MyBulletinBoard) 1.x allows remote attackers to read arbitrary files via a .. (dot dot) …

No fix yet
Fix from $1,600 2006-08-01
Mybulletinboard HIGH 7.5
CVE-2006-3775

SQL injection vulnerability in the init function in class_session.php in MyBB (aka MyBulletinBoard) 1.1.5 allows remote attackers to execute arbitrar…

No fix yet
Fix from $1,950 2006-07-24
Mybulletinboard HIGH 7.5
CVE-2006-3758

inc/init.php in Archive Mode (Light) in MyBB (aka MyBulletinBoard) 1.1.4 calls the extract function with EXTR_OVERWRITE on HTTP POST and GET variable…

Patch available
Fix from $1,950 2006-07-21
Mybulletinboard HIGH 7.5
CVE-2006-3760

Multiple SQL injection vulnerabilities in MyBB (aka MyBulletinBoard) 1.1.4 allow remote attackers to execute arbitrary SQL commands via unspecified v…

Patch available
Fix from $1,950 2006-07-21
Mybulletinboard MEDIUM 5.0
CVE-2006-3759

Unspecified vulnerability in MyBB (aka MyBulletinBoard) 1.1.4, related has unspecified impact and attack vectors related to "user group manipulation."

Patch available
Fix from $1,600 2006-07-21
Mybulletinboard HIGH 7.5
CVE-2006-3420

Cross-site request forgery (CSRF) vulnerability in editpost.php in MyBulletinBoard (MyBB) before 1.1.5 allows remote attackers to perform unauthorize…

Mitigation only
Fix from $1,950 2006-07-07
Mybulletinboard HIGH 7.5
CVE-2006-3243

SQL injection vulnerability in usercp.php in MyBB (MyBulletinBoard) 1.0 through 1.1.3 allows remote attackers to execute arbitrary SQL commands via t…

Patch available
Fix from $1,950 2006-06-27
Mybulletinboard HIGH 7.5
CVE-2006-2908

The domecode function in inc/functions_post.php in MyBulletinBoard (MyBB) 1.1.2, and possibly other versions, allows remote attackers to execute arbi…

Patch available
Fix from $1,950 2006-06-13
Mybulletinboard MEDIUM 6.8
CVE-2006-2949

Cross-site scripting (XSS) vulnerability in private.php in MyBB 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the do param…

Patch available
Fix from $1,600 2006-06-12
Mybulletinboard MEDIUM 6.4
CVE-2006-2589

SQL injection vulnerability in rss.php in MyBB (aka MyBulletinBoard) 1.1.1 allows remote attackers to execute arbitrary SQL commands via the comma pa…

Mitigation only
Fix from $1,600 2006-05-25
Mybulletinboard MEDIUM 6.4
CVE-2006-2333

Multiple SQL injection vulnerabilities in MyBB (aka MyBulletinBoard) 1.1.1 allow remote attackers to execute arbitrary SQL commands via the e-mail ad…

No fix yet
Fix from $1,600 2006-05-12
Mybulletinboard MEDIUM 6.4
CVE-2006-2336

SQL injection vulnerability in showthread.php in MyBB (aka MyBulletinBoard) 1.1.1 allows remote attackers to execute arbitrary SQL commands via the c…

Mitigation only
Fix from $1,600 2006-05-12
Mybulletinboard HIGH 7.5
CVE-2006-1974

SQL injection vulnerability in index.php in MyBB (MyBulletinBoard) before 1.04 allows remote attackers to execute arbitrary SQL commands via the refe…

No fix yet
Fix from $1,950 2006-04-21
Mybulletinboard MEDIUM 5.8
CVE-2006-1912

MyBB (MyBulletinBoard) 1.1.0 does not set the constant KILL_GLOBAL variable in (1) global.php and (2) inc/init.php, which allows remote attackers to …

Mitigation only
Fix from $1,600 2006-04-20
Mybulletinboard MEDIUM 5.1
CVE-2006-1716

Cross-site scripting (XSS) vulnerability in inc/functions_post.php in MyBB (aka MyBulletinBoard) 1.10 allows remote attackers to inject arbitrary web…

Mitigation only
Fix from $1,600 2006-04-11
Mybulletinboard MEDIUM 5.1
CVE-2006-1717

Cross-site scripting (XSS) vulnerability in newthread.php in MyBB (aka MyBulletinBoard) 1.10, when configured to permit new threads by unregistered u…

Mitigation only
Fix from $1,600 2006-04-11
Mybulletinboard MEDIUM 6.8
CVE-2006-1625

Cross-site scripting (XSS) vulnerability in inc/functions_post.php in MyBB (aka MyBulletinBoard) 1.10 allows remote attackers to inject arbitrary web…

Mitigation only
Fix from $1,600 2006-04-05
Mybulletinboard MEDIUM 5.0
CVE-2006-1345

polls.php in MyBB (aka MyBulletinBoard) 1.10 allows remote attackers to obtain sensitive information via a vote action with an "option[]=null" parame…

Mitigation only
Fix from $1,600 2006-03-22
Mybulletinboard MEDIUM 5.0
CVE-2006-1065

SQL injection vulnerability in search.php in MyBulletinBoard (MyBB) 1.04 allows remote attackers to execute arbitrary SQL commands via the forums[] p…

No fix yet
Fix from $1,600 2006-03-07
Mybulletinboard HIGH 7.5
CVE-2006-0959

SQL injection vulnerability in misc.php in MyBulletinBoard (MyBB) 1.03, when register_globals is enabled, allows remote attackers to execute arbitrar…

No fix yet
Fix from $1,950 2006-03-02
Mybulletinboard MEDIUM 6.5
CVE-2006-0638

SQL injection vulnerability in moderation.php in MyBB (aka MyBulletinBoard) 1.0.3 allows remote authenticated users, with certain privileges for mode…

No fix yet
Fix from $1,600 2006-02-10