Vulnerabilities
Vulnerable Software
Scssboard:  >> Scssboard  >> 1.11  Security Vulnerabilities
admin/forums.php in sCssBoard 1.0, 1.1, 1.11, and 1.12 allows remote attackers to bypass authentication and gain administrative access via a large value of the current_user[users_level] parameter.
CVSS Score
7.5
EPSS Score
0.018
Published
2008-12-15
PHP remote file inclusion vulnerability in index.php in sCssBoard 1.0, 1.1, 1.11, and 1.12 allows remote attackers to execute arbitrary PHP code via a URL in the inc_function parameter.
CVSS Score
7.5
EPSS Score
0.008
Published
2008-12-15
Multiple SQL injection vulnerabilities in index.php in sCssBoard 1.0, 1.1, 1.11, and 1.12 allow remote attackers to execute arbitrary SQL commands via (1) the f parameter in a showforum action, (2) the u parameter in a profile action, (3) the viewcat parameter, or (4) a combination of scb_uid and scb_ident cookie values.
CVSS Score
7.5
EPSS Score
0.001
Published
2008-12-15
Cross-site scripting (XSS) vulnerability in sCssBoard 1.11 and earlier allows remote attackers to execute arbitrary Javascript via [url] tags.
CVSS Score
4.3
EPSS Score
0.005
Published
2005-05-02
Unknown vulnerability in sCssBoard 1.11 and earlier has unknown impact, related to "an exploit on the Profile page."
CVSS Score
10.0
EPSS Score
0.004
Published
2005-05-02


Contact Us

Shodan ® - All rights reserved