Vulnerabilities > Azbb

DATE CVE VULNERABILITY TITLE RISK
2006-01-25 CVE-2006-0407 HTML Injection vulnerability in AZ Bulletin Board
Cross-site scripting (XSS) vulnerability in post.php in AZ Bulletin Board (AZbb) 1.1.00 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) nickname parameter and (2) an iframe tag in the topic parameter.
network
azbb
4.3
2005-05-02 CVE-2005-1201 Multiple directory traversal vulnerabilities in AZ Bulletin board (AZbb) before 1.0.08 allow (1) remote authenticated users with administrative privileges to delete arbitrary files via a ..
network
low complexity
azbb
6.4
2005-05-02 CVE-2005-1200 Remote Security vulnerability in Az Bulletin Board 1.0.07A/1.0.07B/1.0.07C
PHP remote file inclusion vulnerability in main_index.php in AZ Bulletin Board (AZbb) 1.0.07a through 1.0.07c allows remote attackers to execute arbitrary PHP code by modifying the (1) dir_src or (2) abs_layer parameter to reference a URL on a remote web server that contains the code.
network
low complexity
azbb
7.5