Boastmachine
7 CVEs tracked since 2005. Since May 2005, none of them reached CISA KEV.
Boastmachine CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2005-05 | 1 | 0 |
| 2005-06 | null or fewer | |
| 2005-07 | null or fewer | |
| 2005-08 | null or fewer | |
| 2005-09 | null or fewer | |
| 2005-10 | null or fewer | |
| 2005-11 | null or fewer | |
| 2005-12 | null or fewer | |
| 2006-01 | 1 | 0 |
| 2006-02 | null or fewer | |
| 2006-03 | null or fewer | |
| 2006-04 | null or fewer | |
| 2006-05 | 1 | 0 |
| 2006-06 | null or fewer | |
| 2006-07 | null or fewer | |
| 2006-08 | null or fewer | |
| 2006-09 | null or fewer | |
| 2006-10 | null or fewer | |
| 2006-11 | null or fewer | |
| 2006-12 | null or fewer | |
| 2007-01 | null or fewer | |
| 2007-02 | null or fewer | |
| 2007-03 | null or fewer | |
| 2007-04 | null or fewer | |
| 2007-05 | 2 | 0 |
| 2007-06 | null or fewer | |
| 2007-07 | null or fewer | |
| 2007-08 | null or fewer | |
| 2007-09 | null or fewer | |
| 2007-10 | 1 | 0 |
| 2007-11 | null or fewer | |
| 2007-12 | null or fewer | |
| 2008-01 | 1 | 0 |
Products
The products that kept showing up in Boastmachine's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 7 most recently published vulnerabilities affecting Boastmachine.
- CVE-2008-0422SQL injection vulnerability in mail.php in boastMachine (aka bMachine) 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.7.5
- CVE-2007-5417Directory traversal vulnerability in index.php in boastMachine (aka bMachine) 2.8 allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter.5.0
- CVE-2007-2932Cross-site scripting (XSS) vulnerability in index.php in BoastMachine allows remote attackers to inject arbitrary web script or HTML via the blog parameter in a content search action.4.3
- CVE-2007-2860user.php in BoastMachine 3.0 platinum allows remote authenticated users to gain privileges via a modified id parameter, as demonstrated by an edit_post action.6.5
- CVE-2006-2491Cross-site scripting (XSS) vulnerability in (1) index.php and (2) bmc/admin.php in BoastMachine (bMachine) 3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the que...6.8
- CVE-2006-0131boastMachine 3.1 allows remote attackers to obtain sensitive information via a direct request to (1) footer.php and (2) side_menu.php, which reveals the path in an error message.5.0
- CVE-2005-1580users.ini.php in BoastMachine 3.0 does not properly restrict the types of files that can be uploaded, which allows remote attackers to execute arbitrary code.7.5
The record
- Peak rank
- #53 in May 2007
- Busiest month shown
- May 2007, 2 CVEs
- Months with a KEV entry
- 0 since May 2005
- Monthly snapshots
- 6 since 2005