VYPR

Azbb

by Azbb

CVEs (2)

  • CVE-2006-0407Jan 25, 2006
    risk 0.03cvss epss 0.03

    Cross-site scripting (XSS) vulnerability in post.php in AZ Bulletin Board (AZbb) 1.1.00 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) nickname parameter and (2) an iframe tag in the topic parameter. NOTE: the original disclosure…

  • CVE-2005-1201May 2, 2005
    risk 0.03cvss epss 0.03

    Multiple directory traversal vulnerabilities in AZ Bulletin board (AZbb) before 1.0.08 allow (1) remote authenticated users with administrative privileges to delete arbitrary files via a .. (dot dot) in the URL to admin_avatar.php or admin_attachment.php or (2) remote attackers…