Mercuryboard is a modestly represented web-based message board and forum platform whose vulnerabilities concentrate in input-handling and data-validation failures, particularly cross-site scripting and SQL injection. The platform's exposure recurs across its message board product line and shows a pattern of acquiring public exploit tooling, reflecting the appeal of web-forum platforms to security researchers and the accessibility of its attack surface. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mercuryboard over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-6632HIGH SQL injection vulnerability in func/login.php in MercuryBoard 1.1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the User-Agent HTTP header ($_SERVER[' | Apr 7, 2009 | 7.5 | 28 | NO | YES |
CVE-2005-2028HIGH SQL injection vulnerability in index.php for MercuryBoard 1.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the User-Agent HTTP header. | Jun 21, 2005 | 7.5 | 28 | NO | YES |
CVE-2005-0414HIGH SQL injection vulnerability in post.php for MercuryBoard 1.1.1 allows remote attackers to execute arbitrary SQL commands via a reply post action for index.php with (1) the t parame | Apr 27, 2005 | 7.5 | 28 | NO | YES |
CVE-2005-0307MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in index.php in MercuryBoard 1.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) s, (2) l, (3) a, (4 | Jan 25, 2005 | 4.3 | 26 | NO | YES |
CVE-2005-0663HIGH SQL injection vulnerability in index.php for MercuryBoard 1.1.2 allows remote attackers to inject arbitrary SQL commands via the f parameter. | May 2, 2005 | 7.5 | 20 | NO | NO |
CVE-2005-0306MEDIUM MercuryBoard 1.1.1 allows remote attackers to gain sensitive information via an HTTP request with the n parameter set to 0, which causes a divide-by-zero error and reveals the path | Jan 25, 2005 | 5.0 | 19 | NO | NO |
CVE-2008-0757MEDIUM Cross-site scripting (XSS) vulnerability in index.php in MercuryBoard 1.1.5 allows remote attackers to inject arbitrary web script or HTML via the message parameter (aka the messag | Feb 13, 2008 | 4.3 | 15 | NO | NO |
CVE-2005-0460MEDIUM index.php in MercuryBoard 1.0.x and 1.1.x allows remote attackers to obtain sensitive information by setting the debug parameter. | May 2, 2005 | 5.0 | 15 | NO | NO |
CVE-2005-0662MEDIUM Cross-site scripting (XSS) vulnerability in index.php for MercuryBoard 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the Avatar field. | May 2, 2005 | 4.3 | 14 | NO | NO |
CVE-2005-0878MEDIUM Cross-site scripting (XSS) vulnerability in MercuryBoard before 1.1.3 allows remote attackers to inject arbitrary web script or HTML via the title field of a PM (private message). | Mar 23, 2005 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mercuryboard.
Media articles that mention a CVE ID that affects a product developed by Mercuryboard — matched by CVE ID, not by vendor name.