newsboard software vulnerabilities
vulnerabilities.aspcode.net
Searching newsboard software vulnerabilities
SQL injection vulnerability in search.inc.php i
vulnerability
|
searchincphp
|
Unclassified
|
NewsBoard
|
injection
|
before
|
SQL
|
SQL injection vulnerability in search.inc.php in Unclassified NewsBoard before 1.5.3 Patch 4 allows remote attackers to execute arbitrary SQL commands via the (1) DateFrom or (2) DateUntil parameter to forum.php.
Directory traversal vulnerability in unb_lib/ab
unb_lib/abbcconfphp
|
vulnerability
|
Unclassified
|
NewsBoard
|
traversal
|
Directory
|
Directory traversal vulnerability in unb_lib/abbc.conf.php in Unclassified NewsBoard (UNB) 1.6.1 patch 1 and earlier, when register_globals is enabled, allows remote attackers to include arbitrary files via .. (dot dot) sequences and a trailing null byte (%00) in the ABBC[Config][smileset] parameter to unb_lib/abbc.css.php.
Directory traversal vulnerability in bb_lib/abb
bb_lib/abbccssphp
|
vulnerability
|
Unclassified
|
NewsBoard
|
traversal
|
Directory
|
Directory traversal vulnerability in bb_lib/abbc.css.php in Unclassified NewsBoard (UNB) 1.5.3-d and possibly earlier versions, when register_globals is enabled, allows remote attackers to include arbitrary files via .. (dot dot) sequences and a trailing null byte (%00) in the design_path parameter. NOTE: this is closely related, but a different vulnerability than the ABBC[Config][smileset] parameter.
Unclassified NewsBoard 1.6.3 stores sensitive i
Unclassified
|
NewsBoard
|
Unclassified NewsBoard 1.6.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain (1) the board log via a direct request for logs/board-YYYY-MM-DD.log, (2) the mail and private message (PM) log via a direct request for logs/email-YY-MM-DD-HH-MM-SS.log, (3) the SQL error message log via a direct request for logs/error-YY-MM.log, and (4) the IP log via a direct request for logs/ip.log.
Software vulnerabilities results 1 to 5 of 5
Page:
1