VYPR

Bilboplanet

by Bilboplanet

CVEs (4)

  • CVE-2014-9919MedMay 15, 2019
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Bilboplanet 2.0. Stored XSS exists in the fullname parameter to signup.php.

  • CVE-2014-9918MedMay 15, 2019
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Bilboplanet 2.0. Stored XSS exists in the user_id parameter to signup.php.

  • CVE-2014-9917MedMay 15, 2019
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Bilboplanet 2.0. There is a stored XSS vulnerability when adding a tag via the user/?page=tribes tags parameter.

  • CVE-2014-9916MedFeb 24, 2017
    risk 0.40cvss 6.1epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in Bilboplanet 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) tribe_name or (2) tags parameter in a tribes page request to user/ or the (3) user_id or (4) fullname parameter to signup.php.

VYPR — Vulnerability Intelligence