Scssboard is a narrowly scoped web application product whose vulnerability profile centers on recurrent input-handling and authentication weaknesses including SQL injection, code injection, and improper authentication mechanisms. The vendor's disclosures tend to acquire public exploit tooling, reflecting the accessibility of web-application flaws to security research and attacker tooling. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Scssboard over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-5576HIGH admin/forums.php in sCssBoard 1.0, 1.1, 1.11, and 1.12 allows remote attackers to bypass authentication and gain administrative access via a large value of the current_user[users_l | Dec 15, 2008 | 7.5 | 29 | NO | YES |
CVE-2008-5578HIGH Multiple SQL injection vulnerabilities in index.php in sCssBoard 1.0, 1.1, 1.11, and 1.12 allow remote attackers to execute arbitrary SQL commands via (1) the f parameter in a show | Dec 15, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-5577HIGH PHP remote file inclusion vulnerability in index.php in sCssBoard 1.0, 1.1, 1.11, and 1.12 allows remote attackers to execute arbitrary PHP code via a URL in the inc_function param | Dec 15, 2008 | 7.5 | 28 | NO | YES |
CVE-2005-1069HIGH Unknown vulnerability in sCssBoard 1.11 and earlier has unknown impact, related to "an exploit on the Profile page." | May 2, 2005 | 10.0 | 25 | NO | NO |
CVE-2005-3837MEDIUM Cross-site scripting (XSS) vulnerability in the search module in sCssBoard 1.2 and 1.12, and earlier versions, allows remote attackers to inject arbitrary web script or HTML via th | Nov 26, 2005 | 4.3 | 14 | NO | NO |
CVE-2005-1068MEDIUM Cross-site scripting (XSS) vulnerability in sCssBoard 1.11 and earlier allows remote attackers to execute arbitrary Javascript via [url] tags. | May 2, 2005 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Scssboard.
Media articles that mention a CVE ID that affects a product developed by Scssboard — matched by CVE ID, not by vendor name.