← Back

Nooms

nooms

3 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Nooms
nooms

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Nooms
1Nooms
Apr 23, 2026
Sep 23, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in db.php in NooMS 1.1 allows remote attackers to conduct brute force attacks against passwords via a username in the g_dbuser parameter and a password in the g_dbpwd parameter, and possibly a "...Show more
Unspecified vulnerability in db.php in NooMS 1.1 allows remote attackers to conduct brute force attacks against passwords via a username in the g_dbuser parameter and a password in the g_dbpwd parameter, and possibly a "localhost" g_dbhost parameter value, related to a "Mysql Remote Brute Force Vulnerability."Show less
1Nooms
1Nooms
Apr 23, 2026
Sep 23, 2008
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in NooMS 1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) page_id parameter to smileys.php and the (2) q parameter to search.php.
1Nooms
1Nooms
Apr 23, 2026
Sep 22, 2008
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Open redirect vulnerability in admin/auth.php in NooMS 1.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the g_site_url parameter.