RSS   Vulnerabilities for 'Elite bulletin board'   RSS

2007-07-06
 
CVE-2007-3592

 

 
PM.php in Elite Bulletin Board before 1.0.10 allows remote authenticated users to delete arbitrary PM messages and conduct other attacks via modified id fields.

 
 
CVE-2007-3591

 

 
Unspecified vulnerability in Profile.php in Elite Bulletin Board before 1.0.10 allows remote attackers to modify profile information via unspecified vectors related to "a remote form," probably related to direct requests and missing authorization checks.

 


Copyright 2024, cxsecurity.com

 

Back to Top