CVE-2022-44216
- EPSS 0.22%
- Veröffentlicht 20.02.2023 20:15:10
- Zuletzt bearbeitet 18.03.2025 16:15:13
Gnuboard 5.5.4 and 5.5.5 is vulnerable to Insecure Permissions. An attacker can change password of all users without knowing victim's original password.
CVE-2022-3963
- EPSS 0.21%
- Veröffentlicht 12.11.2022 22:15:09
- Zuletzt bearbeitet 21.11.2024 07:20:37
A vulnerability was found in gnuboard5. It has been classified as problematic. Affected is an unknown function of the file bbs/faq.php of the component FAQ Key ID Handler. The manipulation of the argument fm_id leads to cross site scripting. It is po...
CVE-2022-30050
- EPSS 0.24%
- Veröffentlicht 16.05.2022 17:15:09
- Zuletzt bearbeitet 21.11.2024 07:02:07
Gnuboard 5.55 and 5.56 is vulnerable to Cross Site Scripting (XSS) via bbs/member_confirm.php.
CVE-2022-1252
- EPSS 0.2%
- Veröffentlicht 11.04.2022 11:15:07
- Zuletzt bearbeitet 24.02.2026 20:18:07
Use of a Broken or Risky Cryptographic Algorithm in GitHub repository gnuboard/gnuboard5 prior to and including 5.5.5. A vulnerability in gnuboard v5.5.5 and below uses weak encryption algorithms leading to sensitive information exposure. This allows...
CVE-2020-18663
- EPSS 0.28%
- Veröffentlicht 24.06.2021 16:15:08
- Zuletzt bearbeitet 21.11.2024 05:08:41
Cross Site Scripting (XSS) vulnerability in gnuboard5 <=v5.3.2.8 via the act parameter in bbs/move_update.php.
CVE-2020-18662
- EPSS 0.34%
- Veröffentlicht 24.06.2021 16:15:08
- Zuletzt bearbeitet 21.11.2024 05:08:41
SQL Injection vulnerability in gnuboard5 <=v5.3.2.8 via the table_prefix parameter in install_db.php.
CVE-2020-18661
- EPSS 0.31%
- Veröffentlicht 24.06.2021 15:15:08
- Zuletzt bearbeitet 21.11.2024 05:08:40
Cross Site Scripting (XSS) vulnerability in gnuboard5 <=v5.3.2.8 via the url parameter to bbs/login.php.
CVE-2018-18674
- EPSS 0.66%
- Veröffentlicht 07.11.2019 21:15:10
- Zuletzt bearbeitet 21.11.2024 03:56:21
GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "board tail contents" parameter, aka the adm/board_form_update.php bo_content_tail parameter.
CVE-2018-18678
- EPSS 0.66%
- Veröffentlicht 30.10.2019 18:15:12
- Zuletzt bearbeitet 21.11.2024 03:56:22
GNUBOARD5 before 5.3.2.0 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "board group extra contents" parameter, aka the adm/boardgroup_form_update.php gr_1~10 parameter.
CVE-2018-18668
- EPSS 0.27%
- Veröffentlicht 26.08.2019 21:15:10
- Zuletzt bearbeitet 21.11.2024 03:56:20
GNUBOARD5 before 5.3.2.0 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "homepage title" parameter, aka the adm/config_form_update.php cf_title parameter.