RSS   Vulnerabilities for 'Bilboplanet'   RSS

2019-05-15
 
CVE-2014-9919

CWE-79
 

 
An issue was discovered in Bilboplanet 2.0. Stored XSS exists in the fullname parameter to signup.php.

 
 
CVE-2014-9918

CWE-79
 

 
An issue was discovered in Bilboplanet 2.0. Stored XSS exists in the user_id parameter to signup.php.

 
 
CVE-2014-9917

CWE-79
 

 
An issue was discovered in Bilboplanet 2.0. There is a stored XSS vulnerability when adding a tag via the user/?page=tribes tags parameter.

 
2017-02-23
 
CVE-2014-9916

 

 
Multiple cross-site scripting (XSS) vulnerabilities in Bilboplanet 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) tribe_name or (2) tags parameter in a tribes page request to user/ or the (3) user_id or (4) fullname parameter to signup.php.

 


Copyright 2019, cxsecurity.com

 

Back to Top