Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
sir gnuboard vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2011-4066
SQL injection vulnerability in bbs/tb.php in Gnuboard 4.33.02 and previous versions allows remote malicious users to execute arbitrary SQL commands via the PATH_INFO.
Sir Gnuboard 3.38
Sir Gnuboard 3.37
Sir Gnuboard
Sir Gnuboard 4.31.03
Sir Gnuboard 3.34
Sir Gnuboard 3.33
Sir Gnuboard 3.32
Sir Gnuboard 3.40
Sir Gnuboard 3.39
Sir Gnuboard 3.31
Sir Gnuboard 3.30
Sir Gnuboard 3.36
Sir Gnuboard 3.35
1 EDB exploit
NA
CVE-2004-1403
PHP remote file inclusion vulnerability in index.php in GNUBoard 3.39 and previous versions allows remote malicious users to execute arbitrary PHP code by modifying the doc parameter to reference a URL on a remote web server that contains the code.
Sir Gnuboard 3.36
Sir Gnuboard 3.37
Sir Gnuboard 3.32
Sir Gnuboard 3.33
Sir Gnuboard 3.30
Sir Gnuboard 3.31
Sir Gnuboard 3.38
Sir Gnuboard 3.39
Sir Gnuboard 3.34
Sir Gnuboard 3.35
NA
CVE-2014-2339
Multiple SQL injection vulnerabilities in bbs/ajax.autosave.php in GNUboard 5.x and possibly earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) subject or (2) content parameter.
Sir Gnuboard 4.34.20
Sir Gnuboard
Sir Gnuboard 4.31.3
Sir Gnuboard 4.33.2
Sir Gnuboard 4.34.21
Sir Gnuboard 4.31.4
1 EDB exploit
7.5
CVSSv3
CVE-2022-44216
Gnuboard 5.5.4 and 5.5.5 is vulnerable to Insecure Permissions. An attacker can change password of all users without knowing victim's original password.
Sir Gnuboard 5.5.5
Sir Gnuboard 5.5.4
6.1
CVSSv3
CVE-2022-30050
Gnuboard 5.55 and 5.56 is vulnerable to Cross Site Scripting (XSS) via bbs/member_confirm.php.
Sir Gnuboard 5.56
Sir Gnuboard 5.55
9.8
CVSSv3
CVE-2005-0269
The file extension check in GNUBoard 3.40 and previous versions only verifies extensions that contain all lowercase letters, which allows remote malicious users to upload arbitrary files via file extensions that include uppercase letters.
Sir Gnuboard
NA
CVE-2012-4873
Cross-site scripting (XSS) vulnerability in the file_download function in GNUBoard prior to 4.34.21 allows remote malicious users to inject arbitrary web script or HTML via the filename parameter.
Sir Gnuboard
1 EDB exploit
NA
CVE-2009-0290
Directory traversal vulnerability in common.php in SIR GNUBoard 4.31.03 allows remote malicious users to include and execute arbitrary local files via a .. (dot dot) in the g4_path parameter. NOTE: in some environments, this can be leveraged for remote code execution via a data: ...
Sir Gnuboard 4.31.03
1 EDB exploit
6.1
CVSSv3
CVE-2021-4293
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as problematic has been found in gnuboard youngcart5 up to 5.4.5.1. Affected is an unknown function of the file adm/menu_list_update.php. The manipulation of the argument me_link leads to cross site scripting. It is possi...
Sir Youngcart5
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2006-4304
CVE-2024-4240
arbitrary
CVE-2024-31601
XSS
CVE-2023-20198
CVE-2024-4256
CVE-2024-3342
encryption
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started