CVE Tools

Boastmachine

7 CVEs tracked since 2005. Since May 2005, none of them reached CISA KEV.

Boastmachine CVEs per month

May 2005 to Jan 2008. Point at a month, or focus the strip and use the arrow keys.
Boastmachine CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2005-0510
2005-06null or fewer
2005-07null or fewer
2005-08null or fewer
2005-09null or fewer
2005-10null or fewer
2005-11null or fewer
2005-12null or fewer
2006-0110
2006-02null or fewer
2006-03null or fewer
2006-04null or fewer
2006-0510
2006-06null or fewer
2006-07null or fewer
2006-08null or fewer
2006-09null or fewer
2006-10null or fewer
2006-11null or fewer
2006-12null or fewer
2007-01null or fewer
2007-02null or fewer
2007-03null or fewer
2007-04null or fewer
2007-0520
2007-06null or fewer
2007-07null or fewer
2007-08null or fewer
2007-09null or fewer
2007-1010
2007-11null or fewer
2007-12null or fewer
2008-0110

Products

The products that kept showing up in Boastmachine's monthly top three, with their CVEs summed over those months.

  1. Boastmachine76 months

Latest CVEs

The 7 most recently published vulnerabilities affecting Boastmachine.

  1. CVE-2008-0422SQL injection vulnerability in mail.php in boastMachine (aka bMachine) 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.7.5
  2. CVE-2007-5417Directory traversal vulnerability in index.php in boastMachine (aka bMachine) 2.8 allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter.5.0
  3. CVE-2007-2932Cross-site scripting (XSS) vulnerability in index.php in BoastMachine allows remote attackers to inject arbitrary web script or HTML via the blog parameter in a content search action.4.3
  4. CVE-2007-2860user.php in BoastMachine 3.0 platinum allows remote authenticated users to gain privileges via a modified id parameter, as demonstrated by an edit_post action.6.5
  5. CVE-2006-2491Cross-site scripting (XSS) vulnerability in (1) index.php and (2) bmc/admin.php in BoastMachine (bMachine) 3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the que...6.8
  6. CVE-2006-0131boastMachine 3.1 allows remote attackers to obtain sensitive information via a direct request to (1) footer.php and (2) side_menu.php, which reveals the path in an error message.5.0
  7. CVE-2005-1580users.ini.php in BoastMachine 3.0 does not properly restrict the types of files that can be uploaded, which allows remote attackers to execute arbitrary code.7.5

The record

Peak rank
#53 in May 2007
Busiest month shown
May 2007, 2 CVEs
Months with a KEV entry
0 since May 2005
Monthly snapshots
6 since 2005
Boastmachine's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store