← Back

Xchangeboard

xchangeboard

Vendor: Xchangeboard • 3 CVEs

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Xchangeboard
1Xchangeboard
Apr 23, 2026
Jul 7, 2008
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in newThread.php in XchangeBoard 1.70 Final and earlier allows remote authenticated users to execute arbitrary SQL commands via the boardID parameter.
1Xchangeboard
1Xchangeboard
Apr 23, 2026
Oct 25, 2006
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Multiple SQL injection vulnerabilities in the checkUser function in inc/DBInterface.php in XchangeBoard 1.70 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via th...Show more
Multiple SQL injection vulnerabilities in the checkUser function in inc/DBInterface.php in XchangeBoard 1.70 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) userNick or (2) password parameters. NOTE: the provenance of this information is unknown; the details are obtained from third party information.Show less
1Xchangeboard
1Xchangeboard
Apr 23, 2026
Oct 25, 2006
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in XchangeBoard 1.70, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the loginNick parameter during login. NOTE: the pr...Show more
SQL injection vulnerability in XchangeBoard 1.70, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the loginNick parameter during login. NOTE: the provenance of this information is unknown; the details are obtained from third party information.Show less