Vulnerability index

Browse CVEs

23 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.0 CVE-2011-3725 DeluxeBB 1.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an e… Deluxebb No fix yet Fix from $1,6002011-09-23 MEDIUM 6.8 CVE-2010-4151 SQL injection vulnerability in misc.php in DeluxeBB 1.3, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute … Deluxebb after 1.3 Fix from $1,6002010-11-03 MEDIUM 6.8 CVE-2010-1859 SQL injection vulnerability in newpost.php in DeluxeBB 1.3 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitra… Deluxebb after 1.3 Fix from $1,6002010-05-07 HIGH 7.5 CVE-2009-4465 DeluxeBB 1.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain user and confi… Deluxebb No fix yet Fix from $1,9502009-12-30 MEDIUM 5.0 CVE-2009-4466 DeluxeBB 1.3 allows remote attackers to obtain sensitive information via a crafted page parameter to misc.php, which reveals the installation path in… Deluxebb No fix yet Fix from $1,6002009-12-30 HIGH 7.5 CVE-2009-1033 SQL injection vulnerability in misc.php in DeluxeBB 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the qorder paramete… Deluxebb after 1.3 Fix from $1,9502009-03-20 MEDIUM 6.8 CVE-2008-6146 SQL injection vulnerability in pm.php in DeluxeBB 1.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQ… Deluxebb after 1.2 Fix from $1,6002009-02-16 HIGH 7.5 CVE-2008-2194 SQL injection vulnerability in forums.php in DeluxeBB 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the sort paramete… Deluxebb after 1.2 Fix from $1,9502008-05-14 MEDIUM 6.5 CVE-2008-2195 Static code injection vulnerability in admincp.php in DeluxeBB 1.2 and earlier allows remote authenticated administrators to inject arbitrary PHP cod… Deluxebb after 1.2 Fix from $1,6002008-05-14 HIGH 9.0 CVE-2007-6237 cp.php in DeluxeBB 1.09 does not verify that the membercookie parameter corresponds to the authenticated member during a profile update, which allows… Deluxebb Mitigation only Fix from $1,9502007-12-04 HIGH 7.5 CVE-2006-5154 PHP remote file inclusion vulnerability in cp/sig.php in DeluxeBB 1.09 and earlier allows remote attackers to execute arbitrary PHP code via a URL in… Deluxebb Patch available Fix from $1,9502006-10-05 HIGH 7.5 CVE-2006-4558 DeluxeBB 1.06 and earlier, when run on the Apache HTTP Server with the mod_mime module, allows remote attackers to execute arbitrary PHP code by uplo… Deluxebb after 1.06 Fix from $1,9502006-09-06 HIGH 7.5 CVE-2006-4078 pm.php (aka the PM system) in DeluxeBB 1.08, and possibly earlier, allows remote attackers to bypass authentication by providing an arbitrary usernam… Deluxebb Patch available Fix from $1,9502006-08-11 MEDIUM 6.8 CVE-2006-4079 Cross-site scripting (XSS) vulnerability in newpost.php in DeluxeBB 1.08, and possibly earlier, allows remote attackers to inject arbitrary web scrip… Deluxebb after 1.08 Fix from $1,6002006-08-11 HIGH 7.5 CVE-2006-3796 DeluxeBB 1.07 and earlier does not properly handle a username composed of a single space character, which allows remote authenticated users to login … Deluxebb after 1.07 Fix from $1,9502006-07-24 HIGH 7.5 CVE-2006-3797 SQL injection vulnerability in DeluxeBB 1.07 and earlier allows remote attackers to bypass authentication, spoof users, and modify settings via the (… Deluxebb Mitigation only Fix from $1,9502006-07-24 HIGH 7.5 CVE-2006-3799 DeluxeBB 1.07 and earlier allows remote attackers to bypass SQL injection protection mechanisms via the login variable and certain other variables, b… Deluxebb Patch available Fix from $1,9502006-07-24 MEDIUM 5.0 CVE-2006-3798 DeluxeBB 1.07 and earlier allows remote attackers to overwrite the (1) _GET, (2) _POST, (3) _ENV, and (4) _SERVER variables via the _COOKIE (aka COOK… Deluxebb Mitigation only Fix from $1,6002006-07-24 HIGH 7.5 CVE-2006-3304 SQL injection vulnerability in cp.php in DeluxeBB 1.07 and earlier allows remote attackers to execute arbitrary SQL commands via the xmsn parameter. Deluxebb after 1.07 Fix from $1,9502006-06-29 MEDIUM 5.1 CVE-2006-2915 Multiple SQL injection vulnerabilities in DeluxeBB 1.06 allow remote attackers to execute arbitrary SQL commands via the (1) hideemail, (2) languagex… Deluxebb Mitigation only Fix from $1,6002006-06-23 MEDIUM 5.1 CVE-2006-2914EPSS 21% PHP remote file inclusion vulnerability in DeluxeBB 1.06 allows remote attackers to execute arbitrary code via a URL in the templatefolder parameter … Deluxebb No fix yet Fix from $1,6002006-06-23 HIGH 7.5 CVE-2006-2503 SQL injection vulnerability in misc.php in DeluxeBB 1.06 allows remote attackers to execute arbitrary SQL commands via the name parameter. Deluxebb No fix yet Fix from $1,9502006-05-22 HIGH 7.5 CVE-2005-2989 Multiple SQL injection vulnerabilities in DeluxeBB 1.0 and 1.0.5 allow remote attackers to execute arbitrary SQL commands via the (1) tid parameter t… Deluxebb Patch available Fix from $1,9502005-09-20