Vulnerabilities
Vulnerable Software
Ekinboard:  Security Vulnerabilities
EkinBoard 1.1.0 and earlier, when register_globals is enabled, allows remote attackers to bypass authorization and gain administrator privileges by setting the _groups[] parameter to 2, as demonstrated via backup.php.
CVSS Score
6.8
EPSS Score
0.014
Published
2009-09-02
Unrestricted file upload vulnerability in EkinBoard 1.1.0 and earlier allows remote attackers to execute arbitrary code by uploading an avatar file with an executable extension followed by a safe extension, then accessing it via a direct request to the file in uploaded/avatars/.
CVSS Score
6.8
EPSS Score
0.027
Published
2009-09-02
SQL injection vulnerability in config.php in EKINboard 1.0.3 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the username cookie.
CVSS Score
7.5
EPSS Score
0.038
Published
2006-03-10
Cross-site scripting (XSS) vulnerability in EKINboard 1.0.3 allows remote attackers to inject arbitrary web script or HTML via a Javascript URI in a BBCode img tag.
CVSS Score
4.3
EPSS Score
0.012
Published
2006-03-10
Cross-site scripting (XSS) vulnerabilities in Ekinboard 1.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter in profile.php and (2) titles of posts.
CVSS Score
4.3
EPSS Score
0.008
Published
2005-11-16


Contact Us

Shodan ® - All rights reserved