Kailash Nadh maintains a narrowly scoped open-source blogging platform, Boastmachine, that represents a niche presence in the vulnerability landscape. The platform's disclosures reflect input and validation handling issues characteristic of web applications, and public exploit code has been developed for vulnerabilities affecting this product. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kailash Nadh over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-2491MEDIUM Cross-site scripting (XSS) vulnerability in (1) index.php and (2) bmc/admin.php in BoastMachine (bMachine) 3.1 and earlier allows remote attackers to inject arbitrary web script or | May 19, 2006 | 6.8 | 27 | NO | YES |
CVE-2006-3827MEDIUM SQL injection vulnerability in bmc/Inc/core/admin/search.inc.php in Kailash Nadh boastMachine (formerly bMachine) 3.1 and earlier allows remote authenticated administrators to exec | Jul 25, 2006 | 6.5 | 17 | NO | NO |
CVE-2006-3828MEDIUM Incomplete blacklist vulnerability in Kailash Nadh boastMachine (formerly bMachine) 3.1 and earlier allows remote authenticated administrators to bypass SQL injection protection me | Jul 25, 2006 | 6.5 | 17 | NO | NO |
CVE-2006-3829MEDIUM Cross-site request forgery (CSRF) vulnerability in bmc/admin.php in Kailash Nadh boastMachine (formerly bMachine) 3.1 and earlier allows remote attackers to perform unauthorized ac | Jul 25, 2006 | 5.0 | 15 | NO | NO |
CVE-2006-3831MEDIUM The Backup selection in Kailash Nadh boastMachine (formerly bMachine) 3.1 and earlier uses predicable filenames for database backups and stores the files under the web root with in | Jul 25, 2006 | 5.0 | 15 | NO | NO |
CVE-2006-3826MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Kailash Nadh boastMachine (formerly bMachine) 3.1 and earlier allow remote attackers to inject arbitrary web script or HTML v | Jul 25, 2006 | 4.3 | 14 | NO | NO |
CVE-2006-3830MEDIUM The Languages selection in the admin interface in Kailash Nadh boastMachine (formerly bMachine) 3.1 and earlier allows remote authenticated administrators to upload files with arbi | Jul 25, 2006 | 4.0 | 13 | NO | NO |
Cross-site scripting (XSS) vulnerability in search.php in boastMachine (bMachine) 2.7, and possibly other versions before 2.9b, allows remote attackers to inject arbitrary web scri | Apr 19, 2006 | 2.6 | 13 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kailash Nadh.
Media articles that mention a CVE ID that affects a product developed by Kailash Nadh — matched by CVE ID, not by vendor name.