Skip to main content

Vendor archive

jamroom CVEs

Beta · best-effort

10 CVEs tagged to vendor jamroom2 Critical, 2 High, 6 Medium, 0 Low, 0 Unrated.

CVE-2012-6705

Published Jun 4, 2017

Cross Site Scripting (XSS) exists in Jamroom before 4.2.7 via the Status Update field.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-5098

Published Oct 20, 2014

Cross-site scripting (XSS) vulnerability in the Search module before 1.2.2 in Jamroom allows remote attackers to inject arbitrary web script or HTML via the query string to search…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6804

Published Dec 5, 2013

Cross-site scripting (XSS) vulnerability in the Search module before 1.1.1 for Jamroom allows remote attackers to inject arbitrary web script or HTML via the search_string paramet…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-2463

Published Jun 25, 2010

Cross-site scripting (XSS) vulnerability in forum.php in Jamroom before 4.1.9 allows remote attackers to inject arbitrary web script or HTML via the post_id parameter in a modify…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1318

Published Apr 17, 2009

Directory traversal vulnerability in index.php in Jamroom 3.1.2, 3.2.3 through 3.2.6, 4.0.2, and possibly other versions before 3.4.0 allows remote attackers to include arbitrary…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3375

Published Jul 30, 2008

The jrCookie function in includes/jamroom-misc.inc.php in JamRoom before 3.4.0 allows remote attackers to bypass authentication and gain administrative access via a boolean value…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-3376

Published Jul 30, 2008

Multiple unspecified vulnerabilities in JamRoom before 3.4.0 have unknown impact and attack vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-2886

Published Jun 27, 2008

PHP remote file inclusion vulnerability in include/plugins/jrBrowser/purchase.php in Jamroom 3.3.0 through 3.3.5, when register_globals is enabled, allows remote attackers to exec…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-2883

Published Jun 26, 2008

PHP remote file inclusion vulnerability in include/plugins/jrBrowser/payment.php in Jamroom 3.3.0 through 3.3.5 allows remote attackers to execute arbitrary PHP code via a URL in…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-5060

Published Sep 28, 2006

Cross-site scripting (XSS) vulnerability in login.php in Jamroom 3.0.16 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the forgot paramete…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-10 of 10 CVEsPage 1 of 1