Vulnerability index

Browse CVEs

31 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 10.0 CVE-2007-1695 PHP remote file inclusion vulnerability in includes/usercp_register.php in phpBB 2.0.19 allows remote attackers to execute arbitrary PHP code via a U… Phpbb Mitigation only Fix from $1,9502007-03-27 MEDIUM 5.0 CVE-2006-2219 phpBB 2.0.20 does not verify user-specified input variable types before being passed to type-dependent functions, which allows remote attackers to ob… Phpbb Mitigation only Fix from $1,6002007-02-08 MEDIUM 6.0 CVE-2006-6508 Cross-site request forgery (CSRF) vulnerability in phpBB 2.0.21 allows remote authenticated users to send unauthorized messages as an arbitrary user … Phpbb Mitigation only Fix from $1,6002006-12-14 MEDIUM 6.0 CVE-2006-6421EPSS 15% Cross-site scripting (XSS) vulnerability in the private message box implementation (privmsg.php) in phpBB 2.0.x allows remote authenticated users to … Phpbb Mitigation only Fix from $1,6002006-12-10 HIGH 7.5 CVE-2006-5209 PHP remote file inclusion vulnerability in admin/admin_topic_action_logging.php in Admin Topic Action Logging Mod 0.95 and earlier, as used in phpBB … Phpbb No fix yet Fix from $1,9502006-10-10 HIGH 7.5 CVE-2006-3940 Multiple SQL injection vulnerabilities in phpbb-Auction allow remote attackers to execute arbitrary SQL commands via (1) the ar parameter in auction_… Phpbb Auction No fix yet Fix from $1,9502006-07-31 HIGH 7.5 CVE-2006-2865 PHP remote file inclusion vulnerability in template.php in phpBB 2 allows remote attackers to execute arbitrary PHP code via a URL in the page parame… Phpbb No fix yet Fix from $1,9502006-06-06 HIGH 7.5 CVE-2006-2360 SQL injection vulnerability in charts.php in the Chart mod for phpBB allows remote attackers to execute arbitrary SQL commands via the id parameter. Phpbb Mitigation only Fix from $1,9502006-05-15 MEDIUM 6.8 CVE-2006-2245EPSS 8% PHP remote file inclusion vulnerability in auction\auction_common.php in Auction mod 1.3m for phpBB allows remote attackers to execute arbitrary PHP … Phpbb Auction Mitigation only Fix from $1,6002006-05-09 MEDIUM 6.4 CVE-2006-2150 PHP remote file inclusion vulnerability in top/list.php in phpBB TopList 1.3.8 and earlier allows remote attackers to include arbitrary files via the… Phpbb Toplist Mitigation only Fix from $1,6002006-05-03 MEDIUM 6.5 CVE-2006-1895 Direct static code injection vulnerability in includes/template.php in phpBB allows remote authenticated users with write access to execute arbitrary… Phpbb No fix yet Fix from $1,6002006-04-20 MEDIUM 6.4 CVE-2006-0632 The gen_rand_string function in phpBB 2.0.19 uses insufficiently random data (small value space) to create the activation key ("validation ID") that … Phpbb No fix yet Fix from $1,6002006-02-10 MEDIUM 5.0 CVE-2006-0438 Cross-site request forgery (CSRF) vulnerability in phpBB 2.0.19, when Link to off-site Avatar or bbcode (IMG) are enabled, allows remote attackers to… Phpbb No fix yet Fix from $1,6002006-02-06 MEDIUM 5.0 CVE-2006-0450EPSS 5% phpBB 2.0.19 and earlier allows remote attackers to cause a denial of service (application crash) by (1) registering many users through profile.php o… Phpbb No fix yet Fix from $1,6002006-01-27 MEDIUM 5.0 CVE-2005-4358 admin/admin_disallow.php in phpBB 2.0.18 allows remote attackers to obtain the installation path via a direct request with a non-empty setmodules par… Phpbb Mitigation only Fix from $1,6002005-12-20 MEDIUM 5.0 CVE-2005-3799 phpBB 2.0.18 allows remote attackers to obtain sensitive information via a large SQL query, which generates an error message that reveals SQL syntax … Phpbb No fix yet Fix from $1,6002005-11-24 HIGH 7.5 CVE-2005-0614EPSS 8% sessions.php in phpBB 2.0.12 and earlier allows remote attackers to gain administrator privileges via the autologinid value in a cookie. Phpbb Mitigation only Fix from $1,9502005-05-02 HIGH 7.5 CVE-2005-1114 Multiple SQL injection vulnerabilities in album_search.php in Photo Album 2.0.53 for phpBB allow remote attackers to execute arbitrary SQL commands v… Phpbb No fix yet Fix from $1,9502005-05-02 HIGH 7.5 CVE-2005-1196 SQL injection vulnerability in kb.php in the Knowledge Base module for phpBB allows remote attackers to obtain sensitive information and execute SQL … Phpbb Mitigation only Fix from $1,9502005-05-02 MEDIUM 5.0 CVE-2005-0659 phpBB 2.0.13 and earlier allows remote attackers to obtain sensitive information via a direct request to oracle.php, which reveals the path in a PHP … Phpbb No fix yet Fix from $1,6002005-05-02 MEDIUM 5.0 CVE-2005-0871 calendar_scheduler.php in Topic Calendar 1.0.1 module for phpBB, when running on a Microsoft IIS server, allows remote attackers to obtain sensitive … Phpbb No fix yet Fix from $1,6002005-05-02 HIGH 7.5 CVE-2005-1047 Meilad File upload script (up.php) mod for phpBB 2.0.x does not properly limit the types of files that can be uploaded, which allows remote authentic… Phpbb Mitigation only Fix from $1,9502005-04-07 HIGH 7.5 CVE-2004-1535EPSS 6% PHP remote file inclusion vulnerability in admin_cash.php for the Cash Mod module for phpBB allows remote attackers to execute arbitrary PHP code by … Phpbb Mitigation only Fix from $1,9502004-12-31 MEDIUM 5.0 CVE-2004-2054 CRLF injection vulnerability in PhpBB 2.0.4 and 2.0.9 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML cont… Phpbb No fix yet Fix from $1,6002004-12-31 MEDIUM 6.8 CVE-2004-0730 Multiple cross-site scripting (XSS) vulnerabilities in PhpBB 2.0.8 allow remote attackers to inject arbitrary web script or HTML via (1) the cat_titl… Phpbb Mitigation only Fix from $1,6002004-07-27 MEDIUM 5.0 CVE-2004-0729 PhpBB 2.0.8 allows remote attackers to gain sensitive information via an invalid (1) category_rows parameter to index.php, (2) faq parameter to faq.p… Phpbb Mitigation only Fix from $1,6002004-07-27 MEDIUM 6.8 CVE-2003-1373 Directory traversal vulnerability in auth.php for PhpBB 1.4.0 through 1.4.4 allows remote attackers to read and include arbitrary files via .. (dot d… Phpbb Mitigation only Fix from $1,6002003-12-31 MEDIUM 6.8 CVE-2003-0484 Cross-site scripting (XSS) vulnerability in viewtopic.php for phpBB allows remote attackers to insert arbitrary web script via the topic_id parameter. Phpbb Mitigation only Fix from $1,6002003-08-07 MEDIUM 5.0 CVE-2002-1707 install.php in phpBB 2.0 through 2.0.1, when "allow_url_fopen" and "register_globals" variables are set to "on", allows remote attackers to execute a… Phpbb Mitigation only Fix from $1,6002002-12-31 MEDIUM 5.1 CVE-2002-0475 Cross-site scripting vulnerability in phpBB 1.4.4 and earlier allows remote attackers to execute arbitrary Javascript on web clients by embedding the… Phpbb Mitigation only Fix from $1,6002002-08-12