Vulnerabilities > Kailash Nadh

DATE CVE VULNERABILITY TITLE RISK
2006-07-25 CVE-2006-3831 Information Disclosure vulnerability in Boastmachine
The Backup selection in Kailash Nadh boastMachine (formerly bMachine) 3.1 and earlier uses predicable filenames for database backups and stores the files under the web root with insufficient access control, which allows remote attackers to obtain sensitive information by downloading a backup file.
network
low complexity
kailash-nadh
5.0
2006-07-25 CVE-2006-3830 Remote Security vulnerability in Boastmachine
The Languages selection in the admin interface in Kailash Nadh boastMachine (formerly bMachine) 3.1 and earlier allows remote authenticated administrators to upload files with arbitrary extensions to the bmc/Inc/Lang directory.
network
low complexity
kailash-nadh
4.0
2006-07-25 CVE-2006-3829 Cross-Site Request Forgery vulnerability in Boastmachine
Cross-site request forgery (CSRF) vulnerability in bmc/admin.php in Kailash Nadh boastMachine (formerly bMachine) 3.1 and earlier allows remote attackers to perform unauthorized actions as an administrator and delete arbitrary user accounts via a delete_user action.
network
low complexity
kailash-nadh
5.0
2006-07-25 CVE-2006-3828 SQL-Injection vulnerability in Boastmachine
Incomplete blacklist vulnerability in Kailash Nadh boastMachine (formerly bMachine) 3.1 and earlier allows remote authenticated administrators to bypass SQL injection protection mechanisms by using commas, quote characters, pound sign (#) characters, "UNION," and "SELECT," which are not filtered by the product, which only checks for "insert," "delete," "update," and "replace."
network
low complexity
kailash-nadh
6.5
2006-07-25 CVE-2006-3827 SQL-Injection vulnerability in Boastmachine
SQL injection vulnerability in bmc/Inc/core/admin/search.inc.php in Kailash Nadh boastMachine (formerly bMachine) 3.1 and earlier allows remote authenticated administrators to execute arbitrary SQL commands via the blog parameter.
network
low complexity
kailash-nadh
6.5
2006-07-25 CVE-2006-3826 Cross-Site Scripting vulnerability in Boastmachine
Multiple cross-site scripting (XSS) vulnerabilities in Kailash Nadh boastMachine (formerly bMachine) 3.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) user_login, (2) full_name, and (3) URL parameters in register.php; and allow remote authenticated administrators to inject arbitrary web script or HTML via the (4) cat_list and (5) key parameters in a certain portion of the admin interface.
network
kailash-nadh
4.3
2006-05-19 CVE-2006-2491 Cross-Site Scripting vulnerability in BoastMachine
Cross-site scripting (XSS) vulnerability in (1) index.php and (2) bmc/admin.php in BoastMachine (bMachine) 3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the query string, which is not properly filtered when it is accessed using the $_SERVER["PHP_SELF"] variable.
6.8
2006-04-19 CVE-2006-1841 Cross-Site Scripting vulnerability in BoastMachine Search.PHP
Cross-site scripting (XSS) vulnerability in search.php in boastMachine (bMachine) 2.7, and possibly other versions before 2.9b, allows remote attackers to inject arbitrary web script or HTML via the key parameter, as used by the search field.
network
high complexity
kailash-nadh
2.6