Vulnerabilities > Azbb
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2006-01-25 | CVE-2006-0407 | HTML Injection vulnerability in AZ Bulletin Board Cross-site scripting (XSS) vulnerability in post.php in AZ Bulletin Board (AZbb) 1.1.00 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) nickname parameter and (2) an iframe tag in the topic parameter. network azbb | 4.3 |
2005-05-02 | CVE-2005-1201 | Multiple directory traversal vulnerabilities in AZ Bulletin board (AZbb) before 1.0.08 allow (1) remote authenticated users with administrative privileges to delete arbitrary files via a .. | 6.4 |
2005-05-02 | CVE-2005-1200 | Remote Security vulnerability in Az Bulletin Board 1.0.07A/1.0.07B/1.0.07C PHP remote file inclusion vulnerability in main_index.php in AZ Bulletin Board (AZbb) 1.0.07a through 1.0.07c allows remote attackers to execute arbitrary PHP code by modifying the (1) dir_src or (2) abs_layer parameter to reference a URL on a remote web server that contains the code. | 7.5 |