Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Zoid Technologies Subscribe
Filtered by product Project Eros Bbsengine
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-3306 1 Zoid Technologies 1 Project Eros Bbsengine 2017-07-19 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the preparestring function in lib/common.php in Project EROS bbsengine before 20060501-0142-jam, and possibly earlier versions dating back to 2006-02-23, might allow remote attackers to inject arbitrary web script or HTML via unknown vectors.
CVE-2006-3307 1 Zoid Technologies 1 Project Eros Bbsengine 2017-07-19 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Project EROS bbsengine before bbsengine-20060429-1550-jam allow remote attackers to execute arbitrary SQL commands via (1) unspecified parameters in the php/comment.php and (2) the getpartialmatches method in php/aolbonics.php.
CVE-2006-3308 1 Zoid Technologies 1 Project Eros Bbsengine 2017-07-19 9.3 HIGH N/A
Unspecified vulnerability in the wpprop code for Project EROS bbsengine before 20060622-0315 has unknown impact and remote attack vectors via [img] tags, possibly cross-site scripting (XSS).