RSS   Vulnerabilities for 'Xmb forum'   RSS

2006-08-04
 
CVE-2006-3994

 

 
SQL injection vulnerability in the u2u_send_recp function in u2u.inc.php in XMB (aka extreme message board) 1.9.6 Alpha and earlier allows remote attackers to execute arbitrary SQL commands via the u2uid parameter to u2u.php, which is directly accessed from $_POST and bypasses the protection scheme.

 
2006-04-12
 
CVE-2006-1748

CWE-Other
 

 
Cross-site scripting (XSS) vulnerability in XMB Forum 1.9.5 allows remote attackers to inject arbitrary web script or HTML by uploading a Flash (.SWF) video that contains a getURL function call, which causes the video to be rendered without disabling ActionScript.

 
2006-01-22
 
CVE-2006-0365

CWE-Other
 

 
Cross-site scripting (XSS) vulnerability in XMB (aka extreme message board) allows remote attackers to inject arbitrary web script or HTML via JavaScript in the SRC attribute of an IMG element.

 
2004-12-31
 
CVE-2004-2588

 

 
Intentional information leak in phpinfo.php in XMB (aka extreme message board) 1.9 beta (aka Nexus beta) allows remote attackers to obtain sensitive information such as the configuration of the web server and the PHP application.

 
2002-06-25
 
CVE-2002-0316

 

 
Cross-site scripting vulnerability in eXtreme message board (XMB) 1.6x and earlier allows remote attackers to execute script as other XMB users by inserting the script into an IMG tag.

 

 >>> Vendor: Xmb software 3 Products
Xmb forum
Extreme message board
U2u instant messenger


Copyright 2024, cxsecurity.com

 

Back to Top