296,335
Total vulnerabilities in the database
Multiple cross-site scripting (XSS) vulnerabilities in Kailash Nadh boastMachine (formerly bMachine) 3.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) user_login, (2) full_name, and (3) URL parameters in register.php; and allow remote authenticated administrators to inject arbitrary web script or HTML via the (4) cat_list and (5) key parameters in a certain portion of the admin interface.
Software | From | Fixed in |
---|---|---|
kailash_nadh / boastmachine | 2.8 | 2.8.x |
kailash_nadh / boastmachine | 2.7 | 2.7.x |
kailash_nadh / boastmachine | 2.9b | 2.9b.x |
kailash_nadh / boastmachine | 2.5 | 2.5.x |
kailash_nadh / boastmachine | 3.1 | 3.1.x |