VYPR
Vendor

Xennobb

Products
1
CVEs
4
Across products
4
Status
Private

Products

1

Recent CVEs

4
  • CVE-2006-4161Aug 16, 2006
    risk 0.04cvss epss 0.09

    Directory traversal vulnerability in the avatar_gallery action in profile.php in XennoBB 2.1.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the category parameter.

  • CVE-2006-4279Aug 21, 2006
    risk 0.03cvss epss 0.02

    SQL injection vulnerability in topic_post.php in XennoBB 2.2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the icon_topic parameter.

  • CVE-2006-4025Aug 9, 2006
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in profile.php in XennoBB 2.1.0 and earlier allows remote authenticated users to execute arbitrary SQL commands via the (1) bday_day, (2) bday_month, and (3) bday_year parameters in the personal section.

  • CVE-2006-3241Jun 27, 2006
    risk 0.00cvss epss 0.00

    Cross-site scripting (XSS) vulnerability in messages.php in XennoBB 1.0.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the tid parameter.