Vulnerabilities > Scssboard

DATE CVE VULNERABILITY TITLE RISK
2008-12-15 CVE-2008-5578 SQL Injection vulnerability in Scssboard
Multiple SQL injection vulnerabilities in index.php in sCssBoard 1.0, 1.1, 1.11, and 1.12 allow remote attackers to execute arbitrary SQL commands via (1) the f parameter in a showforum action, (2) the u parameter in a profile action, (3) the viewcat parameter, or (4) a combination of scb_uid and scb_ident cookie values.
network
low complexity
scssboard CWE-89
7.5
2008-12-15 CVE-2008-5577 Code Injection vulnerability in Scssboard
PHP remote file inclusion vulnerability in index.php in sCssBoard 1.0, 1.1, 1.11, and 1.12 allows remote attackers to execute arbitrary PHP code via a URL in the inc_function parameter.
network
low complexity
scssboard CWE-94
7.5
2008-12-15 CVE-2008-5576 Improper Authentication vulnerability in Scssboard
admin/forums.php in sCssBoard 1.0, 1.1, 1.11, and 1.12 allows remote attackers to bypass authentication and gain administrative access via a large value of the current_user[users_level] parameter.
network
low complexity
scssboard CWE-287
7.5
2005-11-26 CVE-2005-3837 Cross-Site Scripting vulnerability in SCSSBoard Search Module
Cross-site scripting (XSS) vulnerability in the search module in sCssBoard 1.2 and 1.12, and earlier versions, allows remote attackers to inject arbitrary web script or HTML via the search_term parameter.
network
scssboard
4.3
2005-05-02 CVE-2005-1069 Remote Security vulnerability in sCssBoard
Unknown vulnerability in sCssBoard 1.11 and earlier has unknown impact, related to "an exploit on the Profile page."
network
low complexity
scssboard
critical
10.0
2005-05-02 CVE-2005-1068 Cross-site scripting (XSS) vulnerability in sCssBoard 1.11 and earlier allows remote attackers to execute arbitrary Javascript via [url] tags.
network
scssboard
4.3