Vulnerabilities > Kailash Nadh > Boastmachine > 3.1

DATE CVE VULNERABILITY TITLE RISK
2006-07-25 CVE-2006-3830 Remote Security vulnerability in Boastmachine
The Languages selection in the admin interface in Kailash Nadh boastMachine (formerly bMachine) 3.1 and earlier allows remote authenticated administrators to upload files with arbitrary extensions to the bmc/Inc/Lang directory.
network
low complexity
kailash-nadh
4.0
2006-07-25 CVE-2006-3829 Cross-Site Request Forgery vulnerability in Boastmachine
Cross-site request forgery (CSRF) vulnerability in bmc/admin.php in Kailash Nadh boastMachine (formerly bMachine) 3.1 and earlier allows remote attackers to perform unauthorized actions as an administrator and delete arbitrary user accounts via a delete_user action.
network
low complexity
kailash-nadh
5.0
2006-07-25 CVE-2006-3828 SQL-Injection vulnerability in Boastmachine
Incomplete blacklist vulnerability in Kailash Nadh boastMachine (formerly bMachine) 3.1 and earlier allows remote authenticated administrators to bypass SQL injection protection mechanisms by using commas, quote characters, pound sign (#) characters, "UNION," and "SELECT," which are not filtered by the product, which only checks for "insert," "delete," "update," and "replace."
network
low complexity
kailash-nadh
6.5
2006-07-25 CVE-2006-3827 SQL-Injection vulnerability in Boastmachine
SQL injection vulnerability in bmc/Inc/core/admin/search.inc.php in Kailash Nadh boastMachine (formerly bMachine) 3.1 and earlier allows remote authenticated administrators to execute arbitrary SQL commands via the blog parameter.
network
low complexity
kailash-nadh
6.5
2006-07-25 CVE-2006-3826 Cross-Site Scripting vulnerability in Boastmachine
Multiple cross-site scripting (XSS) vulnerabilities in Kailash Nadh boastMachine (formerly bMachine) 3.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) user_login, (2) full_name, and (3) URL parameters in register.php; and allow remote authenticated administrators to inject arbitrary web script or HTML via the (4) cat_list and (5) key parameters in a certain portion of the admin interface.
network
kailash-nadh
4.3