CVE-2006-3826
- EPSS 0.62%
- Veröffentlicht 25.07.2006 13:22:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Multiple cross-site scripting (XSS) vulnerabilities in Kailash Nadh boastMachine (formerly bMachine) 3.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) user_login, (2) full_name, and (3) URL parameters in regist...
CVE-2006-3827
- EPSS 0.82%
- Veröffentlicht 25.07.2006 13:22:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
SQL injection vulnerability in bmc/Inc/core/admin/search.inc.php in Kailash Nadh boastMachine (formerly bMachine) 3.1 and earlier allows remote authenticated administrators to execute arbitrary SQL commands via the blog parameter.
CVE-2006-3828
- EPSS 0.38%
- Veröffentlicht 25.07.2006 13:22:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Incomplete blacklist vulnerability in Kailash Nadh boastMachine (formerly bMachine) 3.1 and earlier allows remote authenticated administrators to bypass SQL injection protection mechanisms by using commas, quote characters, pound sign (#) characters,...
- EPSS 0.57%
- Veröffentlicht 25.07.2006 13:22:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Cross-site request forgery (CSRF) vulnerability in bmc/admin.php in Kailash Nadh boastMachine (formerly bMachine) 3.1 and earlier allows remote attackers to perform unauthorized actions as an administrator and delete arbitrary user accounts via a del...
- EPSS 0.25%
- Veröffentlicht 25.07.2006 13:22:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
The Languages selection in the admin interface in Kailash Nadh boastMachine (formerly bMachine) 3.1 and earlier allows remote authenticated administrators to upload files with arbitrary extensions to the bmc/Inc/Lang directory. NOTE: because the upl...
- EPSS 0.43%
- Veröffentlicht 25.07.2006 13:22:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
The Backup selection in Kailash Nadh boastMachine (formerly bMachine) 3.1 and earlier uses predicable filenames for database backups and stores the files under the web root with insufficient access control, which allows remote attackers to obtain sen...
CVE-2006-2491
- EPSS 10.96%
- Veröffentlicht 19.05.2006 23:02:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Cross-site scripting (XSS) vulnerability in (1) index.php and (2) bmc/admin.php in BoastMachine (bMachine) 3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the query string, which is not properly filtered when it is ...
CVE-2006-1841
- EPSS 0.43%
- Veröffentlicht 19.04.2006 16:06:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Cross-site scripting (XSS) vulnerability in search.php in boastMachine (bMachine) 2.7, and possibly other versions before 2.9b, allows remote attackers to inject arbitrary web script or HTML via the key parameter, as used by the search field.