Vulnerabilities > Ideal Science

DATE CVE VULNERABILITY TITLE RISK
2006-05-12 CVE-2006-2321 Input Validation vulnerability in IdealBB
Multiple cross-site scripting (XSS) vulnerabilities in Ideal Science Ideal BB 1.5.4a and earlier allow remote attackers to inject arbitrary web script or HTML via unknown vectors.
network
ideal-science
4.3
2006-05-12 CVE-2006-2320 Input Validation vulnerability in IdealBB
Multiple SQL injection vulnerabilities in Ideal Science Ideal BB 1.5.4a and earlier allow remote attackers to execute arbitrary SQL commands via multiple unspecified vectors related to stored procedure calls.
network
low complexity
ideal-science
7.5
2006-05-12 CVE-2006-2319 Input Validation vulnerability in IdealBB
Ideal Science Ideal BB 1.5.4a and earlier does not properly check file extensions before permitting an upload, which allows remote attackers to upload and execute an ASP script via a 0x00 character before the ".asp" portion of the filename.
network
low complexity
ideal-science
5.0
2006-05-12 CVE-2006-2318 Input Validation vulnerability in IdealBB
Incomplete blacklist vulnerability in Ideal Science Ideal BB 1.5.4a and earlier allows remote attackers to upload and execute an ASP script via a ".asa" file, which bypasses the check for the ".asp" extension but is executable on the server.
network
low complexity
ideal-science
7.5
2006-05-12 CVE-2006-2317 Input Validation vulnerability in IdealBB
Unspecified vulnerability in Ideal Science Ideal BB 1.5.4a and earlier allows remote attackers to read arbitrary files under the web root via unspecified attack vectors related to the OpenTextFile method in Scripting.FileSystemObject.
network
low complexity
ideal-science
5.0
2005-12-08 CVE-2005-4078 Cross-Site Scripting vulnerability in Ideal Bb.Net
Multiple cross-site scripting (XSS) vulnerabilities in Ideal BB.NET 1.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) forumID, (2) boardID, and (3) topicRepeater1-p parameters in topics.aspx, (4) boardID parameter in categoryindex.aspx, (5) postID parameter in posts.aspx, (6) catID parameter in forums.aspx, and (7) memberID parameter in member.aspx.
network
ideal-science
4.3
2004-12-31 CVE-2004-2209 Remote Input Validation vulnerability in Ideal Science IdealBB
SQL injection vulnerability in Ideal Science IdealBB 1.4.9 through 1.5.3 allows remote attackers to execute arbitrary SQL commands via unknown vectors.
network
low complexity
ideal-science
7.5
2004-12-31 CVE-2004-2208 Remote Input Validation vulnerability in Ideal Science IdealBB
CRLF injection vulnerability in Ideal Science IdealBB 1.4.9 through 1.5.3 allows remote attackers to conduct HTTP response splitting attacks via unknown vectors.
network
low complexity
ideal-science
5.0
2004-12-31 CVE-2004-2207 Remote Input Validation vulnerability in Ideal Science IdealBB
Cross-site scripting (XSS) vulnerability in Ideal Science IdealBB 1.4.9 through 1.5.3 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
network
ideal-science
4.3