Lucene search

K

Simple Security Vulnerabilities

cve
cve

CVE-2008-0775

Cross-site scripting (XSS) vulnerability in sboxDB.php in Simple Machines Forum (SMF) Shoutbox 1.14 through 1.16b allows remote attackers to inject arbitrary web script or HTML via strings to the shoutbox form that start with "&#", contain the desired script, and end with...

5.8AI Score

0.003EPSS

2008-02-14 12:00 AM
28
cve
cve

CVE-2008-0284

Cross-site scripting (XSS) vulnerability in Simple Machines Forum (SMF) 1.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) Itemid or (2) topic...

5.7AI Score

0.002EPSS

2008-01-15 09:00 PM
18
cve
cve

CVE-2007-5953

Unspecified vulnerability in Really Simple CalDAV Store (RSCDS) before 0.9.0 allows attackers to obtain sensitive information via unspecified...

6AI Score

0.003EPSS

2007-11-14 01:46 AM
20
cve
cve

CVE-2007-5943

Simple Machines Forum (SMF) 1.1.4 allows remote attackers to read a message in private forums by using the advanced search module with the "show results as messages" option, then searching for possible keywords contained in that...

6.6AI Score

0.003EPSS

2007-11-14 01:46 AM
23
cve
cve

CVE-2007-5646

SQL injection vulnerability in Sources/Search.php in Simple Machines Forum (SMF) 1.1.3, when MySQL 5 is used, allows remote attackers to execute arbitrary SQL commands via the userspec parameter in a search2 action to...

8.3AI Score

0.007EPSS

2007-10-23 09:47 PM
32
cve
cve

CVE-2007-5564

Multiple cross-site scripting (XSS) vulnerabilities in NSSboard (formerly Simple PHP Forum) 6.1 allow remote attackers to inject arbitrary web script or HTML via (1) HTML tags when BBcode is disabled; or the (2) user, (3) email, or (4) Real Name fields in a...

5.8AI Score

0.002EPSS

2007-10-18 08:17 PM
22
cve
cve

CVE-2007-3888

Multiple cross-site scripting (XSS) vulnerabilities in Insanely Simple Blog 0.5 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the search action, possibly related to the term parameter to index.php; or (2) an anonymous blog entry, possibly involving the (a)...

5.9AI Score

0.008EPSS

2007-07-18 11:30 PM
20
cve
cve

CVE-2007-3889

Multiple SQL injection vulnerabilities in Insanely Simple Blog 0.5 and earlier allow remote attackers to execute arbitrary SQL commands via the current_subsection parameter to index.php and other unspecified...

8.5AI Score

0.009EPSS

2007-07-18 11:30 PM
20
cve
cve

CVE-2007-3430

SQL injection vulnerability in index.php in Simple Invoices 2007 05 25 allows remote attackers to execute arbitrary SQL commands via the submit parameter in an email...

8.4AI Score

0.008EPSS

2007-06-27 12:30 AM
22
cve
cve

CVE-2007-3308

Simple Machines Forum (SMF) 1.1.2 uses a concatenation method with insufficient randomization when creating a WAV file CAPTCHA, which allows remote attackers to pass the CAPTCHA test via an automated brute-force...

6.5AI Score

0.008EPSS

2007-06-21 01:30 AM
25
cve
cve

CVE-2007-3309

Unspecified vulnerability in Simple Machines Forum (SMF) 1.1.2 allows remote attackers to execute arbitrary PHP code during (1) creation or (2) editing of a...

7.6AI Score

0.016EPSS

2007-06-21 01:30 AM
26
cve
cve

CVE-2007-2546

Session fixation vulnerability in Simple Machines Forum (SMF) 1.1.2 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID...

6.7AI Score

0.02EPSS

2007-05-09 10:19 AM
17
cve
cve

CVE-2007-1982

Multiple PHP remote file inclusion vulnerabilities in Really Simple PHP and Ajax (RSPA) 2007-03-23 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) __IncludeFilePHPClass, (2) __ClassPath, and (3) __class parameters to (a) rspa/framework/Controller_v5.php, and...

7.6AI Score

0.024EPSS

2007-04-12 01:19 AM
20
2
cve
cve

CVE-2007-1851

Multiple directory traversal vulnerabilities in Really Simple PHP and Ajax (RSPA) 2007-03-23 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the __class parameter to (1) Controller_v4.php or (2)...

7.4AI Score

0.01EPSS

2007-04-03 04:19 PM
20
cve
cve

CVE-2007-1341

include/auth/auth.php in Simple Invoices before 2007 03 05 does not use the login system to protect print preview pages for invoices, which might allow attackers to obtain sensitive...

6.3AI Score

0.004EPSS

2007-03-08 10:19 PM
29
cve
cve

CVE-2006-7088

Multiple SQL injection vulnerabilities in Simple PHP Forum before 0.4 allow remote attackers to execute arbitrary SQL commands via the username parameter to (1) logon_user.php and (2)...

9AI Score

0.002EPSS

2007-03-02 09:18 PM
21
cve
cve

CVE-2007-0787

PHP remote file inclusion vulnerability in controller.php in Simple Invoices before 20070202 allows remote attackers to execute arbitrary PHP code via a URL in the (1) module or (2) view parameter. NOTE: some of these details are obtained from third party...

7.5AI Score

0.024EPSS

2007-02-06 07:28 PM
23
cve
cve

CVE-2007-0399

Multiple cross-site scripting (XSS) vulnerabilities in index.php in Simple Machines Forum (SMF) 1.1 RC3 allow remote authenticated users to inject arbitrary web script or HTML via the (1) recipient or (2) BCC field when selecting send in a pm...

5.4AI Score

0.009EPSS

2007-01-22 06:28 PM
21
cve
cve

CVE-2006-6763

Multiple PHP remote file inclusion vulnerabilities in the Keep It Simple Guest Book (KISGB) allow remote attackers to execute arbitrary PHP code via a URL in the (1) path_to_themes parameter in (a) authenticate.php, and the (2) default_path_for_themes parameter in (b) admin.php and (c)...

8AI Score

0.005EPSS

2006-12-27 02:28 AM
23
cve
cve

CVE-2006-6764

PHP remote file inclusion vulnerability in authenticate.php in Keep It Simple Guest Book (KISGB), when executing PHP through CGI, allows remote attackers to execute arbitrary PHP code via a URL in the default_path_to_themes...

7.9AI Score

0.012EPSS

2006-12-27 02:28 AM
23
cve
cve

CVE-2006-6375

Cross-site scripting (XSS) vulnerability in display.php in Simple Machines Forum (SMF) 1.1 Final and earlier allows remote attackers to inject arbitrary web script or HTML via the contents of a file that is uploaded with the image parameter set, which can be interpreted as script by Internet...

5.9AI Score

0.041EPSS

2006-12-07 05:28 PM
19
cve
cve

CVE-2006-5503

Cross-site scripting (XSS) vulnerability in index.php in Simple Machines Forum (SMF) 1.1 RC2 allows remote attackers to inject arbitrary web script or HTML via the action...

6AI Score

0.003EPSS

2006-10-25 10:07 PM
18
cve
cve

CVE-2006-5504

Cross-site scripting (XSS) vulnerability in index.php in Simple Machines Forum (SMF) allows remote attackers to inject arbitrary web script or HTML via a base64 encoded params value in the action...

5.9AI Score

0.007EPSS

2006-10-25 10:07 PM
23
cve
cve

CVE-2006-4918

Multiple PHP remote file inclusion vulnerabilities in Simple Discussion Board 0.1.0 allow remote attackers to execute arbitrary PHP code via a URL in the (1) env_dir parameter to (a) blank.php, (b) admin.php, or (c) builddb.php, and the (2) script_root parameter to...

8AI Score

0.153EPSS

2006-09-21 01:07 AM
20
cve
cve

CVE-2006-4467

Simple Machines Forum (SMF) 1.1RCx before 1.1RC3, and 1.0.x before 1.0.8, does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to perform directory traversal attacks to read...

6.8AI Score

0.054EPSS

2006-08-31 08:04 PM
20
cve
cve

CVE-2006-4122

Simple one-file guestbook 1.0 and earlier allows remote attackers to bypass authentication and delete guestbook entries via a modified id parameter to...

7.3AI Score

0.055EPSS

2006-08-14 11:04 PM
21
cve
cve

CVE-2006-0896

Cross-site scripting (XSS) vulnerability in Sources/Register.php in Simple Machine Forum (SMF) 1.0.6 allows remote attackers to inject arbitrary web script or HTML via the X-Forwarded-For HTTP header...

5.7AI Score

0.013EPSS

2006-02-25 11:02 AM
19
cve
cve

CVE-2006-0112

Cross-site scripting (XSS) vulnerability in index.php in Enhanced Simple PHP Gallery 1.7 allows remote attackers to inject arbitrary web script or HTML via the dir...

5.8AI Score

0.003EPSS

2006-01-07 01:03 AM
27
cve
cve

CVE-2006-0113

Enhanced Simple PHP Gallery 1.7 allows remote attackers to obtain the full path of the application via a direct request to sp_helper_functions.php, which leaks the pathname in an error...

6.6AI Score

0.006EPSS

2006-01-07 01:03 AM
26
cve
cve

CVE-2005-2817

Simple Machines Forum (SMF) 1-0-5 and earlier supports the use of URLs for avatar images, which allows remote attackers to monitor sensitive information of forum visitors such as IP address and user agent, as demonstrated using a PHP script on a malicious...

6.4AI Score

0.01EPSS

2005-09-07 07:07 PM
37
cve
cve

CVE-2004-1996

Cross-site scripting (XSS) vulnerability in Simple Machines Forum (SMF) 1.0 allows remote attackers to inject arbitrary web script via the size...

6.1AI Score

0.004EPSS

2005-05-10 04:00 AM
25
cve
cve

CVE-2002-0463

home.php in ARSC (Really Simple Chat) 1.0.1 and earlier allows remote attackers to determine the full pathname of the web server via an invalid language in the arsc_language parameter, which leaks the pathname in an error...

7.1AI Score

0.004EPSS

2003-04-02 05:00 AM
23
Total number of security vulnerabilities432