VendorsMercuryboardmercuryboard_message_boardall versions
Vulnerabilities

Mercuryboard Mercuryboard Message Board

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2005-2028
SQL injection vulnerability in index.php for MercuryBoard 1.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the User-Agent HTTP header.
Published 2005-06-21 · Modified
7.51 PoCEPSS 0.021
CVE-2005-0878
Cross-site scripting (XSS) vulnerability in MercuryBoard before 1.1.3 allows remote attackers to inject arbitrary web script or HTML via the title field of a PM (private message).
Published 2005-03-26 · Modified
4.3EPSS 0.012
CVE-2008-0757
Cross-site scripting (XSS) vulnerability in index.php in MercuryBoard 1.1.5 allows remote attackers to inject arbitrary web script or HTML via the message parameter (aka the message text area), which leads to an injection in the messenger during private message (PM) preview. NOTE: some of these details are obtained from third party information.
Published 2008-02-13 · Modified
4.3EPSS 0.011