CVE-2014-2023
- EPSS 9.4%
- Veröffentlicht 26.10.2017 20:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Multiple SQL injection vulnerabilities in the Tapatalk plugin 4.9.0 and earlier and 5.x through 5.2.1 for vBulletin allow remote attackers to execute arbitrary SQL commands via a crafted xmlrpc API request to (1) unsubscribe_forum.php or (2) unsubscr...
CVE-2017-14652
- EPSS 1.4%
- Veröffentlicht 21.09.2017 20:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
SQL Injection vulnerability in mobiquo/lib/classTTForum.php in the Tapatalk plugin before 4.5.8 for MyBB allows an unauthenticated remote attacker to inject arbitrary SQL commands via an XML-RPC encoded document sent as part of the user registration ...
CVE-2014-8870
- EPSS 0.25%
- Veröffentlicht 15.01.2015 15:59:16
- Zuletzt bearbeitet 12.04.2025 10:46:40
Open redirect vulnerability in mobiquo/smartbanner/welcome.php in the Tapatalk (com.tapatalk.wbb4) plugin before 1.1.2 for Woltlab Burning Board 4.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a U...
CVE-2014-8869
- EPSS 0.38%
- Veröffentlicht 15.01.2015 15:59:15
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple cross-site scripting (XSS) vulnerabilities in mobiquo/smartbanner/welcome.php in the Tapatalk (com.tapatalk.wbb4) plugin 1.x before 1.1.2 for Woltlab Burning Board 4.0 allow remote attackers to inject arbitrary web script or HTML via the (1)...
CVE-2014-5680
- EPSS 0.1%
- Veröffentlicht 09.09.2014 01:55:47
- Zuletzt bearbeitet 12.04.2025 10:46:40
The Tapatalk (aka com.quoord.tapatalkpro.activity) application 4.8.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate...