RSS   Vulnerabilities for 'Myphp forum'   RSS

2008-01-07
 
CVE-2008-0099

 

 
Multiple SQL injection vulnerabilities in MyPHP Forum 3.0 and earlier allow remote attackers to execute arbitrary SQL commands via the searchtext parameter to search.php, and unspecified other vectors.

 
2005-05-03
 
CVE-2005-1404

 

 
MyPHP Forum 1.0 allows remote attackers to spoof the username by modifying the (1) nbuser parameter to post.php or (2) sender parameter to privmsg.php.

 
2005-04-27
 
CVE-2005-0413

 

 
Multiple SQL injection vulnerabilities in MyPHP Forum 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the fid in forum.php, (2) the member parameter in member.php, (3) the email parameter in forgot.php, or (4) the nbuser or nbpass parameters in include.php. NOTE: it was later reported that vector 2 exists in 3.0 and earlier.

 


Copyright 2024, cxsecurity.com

 

Back to Top