Vulnerabilities > Mybulletinboard > Mybulletinboard > 1.14

DATE CVE VULNERABILITY TITLE RISK
2006-09-25 CVE-2006-4972 Cross-Site Scripting vulnerability in MyBulletinBoard
Cross-site scripting (XSS) vulnerability in archive/index.php/forum-4.html in MyBB (aka MyBulletinBoard) allows remote attackers to inject arbitrary web script or HTML via the navbits[][name] parameter.
network
high complexity
mybulletinboard
5.1
2006-09-25 CVE-2006-4971 Information Disclosure vulnerability in MyBulletinBoard
MyBB (aka MyBulletinBoard) allows remote attackers to obtain sensitive information via a direct request for inc/plugins/hello.php, which reveals the path in an error message.
network
low complexity
mybulletinboard
5.0
2006-08-01 CVE-2006-3954 Directory Traversal vulnerability in MyBulletinBoard
Directory traversal vulnerability in usercp.php in MyBB (aka MyBulletinBoard) 1.x allows remote attackers to read arbitrary files via a ..
network
low complexity
mybulletinboard
5.0
2006-08-01 CVE-2006-3953 Cross-Site Scripting vulnerability in MyBulletinBoard UserCP.PHP
Cross-site scripting (XSS) vulnerability in usercp.php in MyBB (aka MyBulletinBoard) 1.x allows remote attackers to inject arbitrary web script or HTML via the gallery parameter.
network
mybulletinboard
4.3