Vulnerability index

Browse CVEs

69 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Phpbb HIGH 7.5
CVE-2005-3416

phpBB 2.0.17 and earlier, when register_globals is enabled and the session_start function has not been called to handle a session, allows remote atta…

Patch available
Fix from $1,950 2005-11-01
Phpbb HIGH 7.5
CVE-2005-3417

phpBB 2.0.17 and earlier, when the register_long_arrays directive is disabled, allows remote attackers to modify global variables and bypass security…

Patch available
Fix from $1,950 2005-11-01
Phpbb HIGH 7.5
CVE-2005-3419

SQL injection vulnerability in usercp_register.php in phpBB 2.0.17 allows remote attackers to execute arbitrary SQL commands via the signature_bbcode…

Patch available
Fix from $1,950 2005-11-01
Phpbb HIGH 7.5
CVE-2005-3420

usercp_register.php in phpBB 2.0.17 allows remote attackers to modify regular expressions and execute PHP code via the signature_bbcode_uid parameter…

Patch available
Fix from $1,950 2005-11-01
Phpbb HIGH 7.5
CVE-2005-2086EPSS 85%

PHP remote file inclusion vulnerability in viewtopic.php in phpBB 2.0.15 and earlier allows remote attackers to execute arbitrary PHP code.

Patch available
Fix from $1,950 2005-07-05
Phpbb HIGH 7.5
CVE-2005-1193EPSS 16%

The bbencode_second_pass and make_clickable functions in bbcode.php for phpBB before 2.0.15, as used in viewtopic.php, privmsg.php, and other scripts…

Patch available
Fix from $1,950 2005-05-16
Phpbb HIGH 7.5
CVE-2005-0614EPSS 8%

sessions.php in phpBB 2.0.12 and earlier allows remote attackers to gain administrator privileges via the autologinid value in a cookie.

Mitigation only
Fix from $1,950 2005-05-02
Phpbb HIGH 7.5
CVE-2005-1114

Multiple SQL injection vulnerabilities in album_search.php in Photo Album 2.0.53 for phpBB allow remote attackers to execute arbitrary SQL commands v…

No fix yet
Fix from $1,950 2005-05-02
Phpbb HIGH 7.5
CVE-2005-1196

SQL injection vulnerability in kb.php in the Knowledge Base module for phpBB allows remote attackers to obtain sensitive information and execute SQL …

Mitigation only
Fix from $1,950 2005-05-02
Phpbb MEDIUM 5.0
CVE-2005-0659

phpBB 2.0.13 and earlier allows remote attackers to obtain sensitive information via a direct request to oracle.php, which reveals the path in a PHP …

No fix yet
Fix from $1,600 2005-05-02
Phpbb MEDIUM 5.0
CVE-2005-0871

calendar_scheduler.php in Topic Calendar 1.0.1 module for phpBB, when running on a Microsoft IIS server, allows remote attackers to obtain sensitive …

No fix yet
Fix from $1,600 2005-05-02
Phpbb Auction MEDIUM 5.0
CVE-2005-1234

Multiple SQL injection vulnerabilities in phpbb-Auction allow remote attackers to execute arbitrary SQL commands via the (1) u parameter to auction_r…

Patch available
Fix from $1,600 2005-05-02
Phpbb Auction MEDIUM 5.0
CVE-2005-1235

auction_my_auctions.php in phpbb-Auction 1.2m and earlier allows remote attackers to obtain sensitive information via an invalid mode parameter, whic…

Patch available
Fix from $1,600 2005-05-02
Phpbb HIGH 7.5
CVE-2005-1047

Meilad File upload script (up.php) mod for phpBB 2.0.x does not properly limit the types of files that can be uploaded, which allows remote authentic…

Mitigation only
Fix from $1,950 2005-04-07
Phpbb MEDIUM 6.4
CVE-2005-0259

phpBB 2.0.11, and possibly other versions, with remote avatars and avatar uploading enabled, allows local users to read arbitrary files by providing …

Patch available
Fix from $1,600 2005-03-14
Phpbb MEDIUM 5.0
CVE-2005-0258

Directory traversal vulnerability in (1) usercp_register.php and (2) usercp_avatar.php for phpBB 2.0.11, and possibly other versions, with gallery av…

Patch available
Fix from $1,600 2005-03-14
Phpbb MEDIUM 5.0
CVE-2005-0603

viewtopic.php in phpBB 2.0.12 and earlier allows remote attackers to obtain sensitive information via a highlight parameter containing invalid regula…

Patch available
Fix from $1,600 2005-02-28
Phpbb HIGH 7.5
CVE-2004-1535EPSS 6%

PHP remote file inclusion vulnerability in admin_cash.php for the Cash Mod module for phpBB allows remote attackers to execute arbitrary PHP code by …

Mitigation only
Fix from $1,950 2004-12-31
Phpbb HIGH 7.5
CVE-2004-2350

SQL injection vulnerability in search.php for phpBB 1.0 through 2.0.6 allows remote attackers to execute arbitrary SQL and gain privileges via the se…

Patch available
Fix from $1,950 2004-12-31
Phpbb MEDIUM 5.0
CVE-2004-2054

CRLF injection vulnerability in PhpBB 2.0.4 and 2.0.9 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML cont…

No fix yet
Fix from $1,600 2004-12-31
Phpbb MEDIUM 6.8
CVE-2004-0339

Cross-site scripting (XSS) vulnerability in ViewTopic.php in phpBB, possibly 2.0.6c and earlier, allows remote attackers to execute arbitrary script …

Patch available
Fix from $1,600 2004-11-23
Phpbb HIGH 7.5
CVE-2004-1315EPSS 72%

viewtopic.php in phpBB 2.x before 2.0.11 improperly URL decodes the highlight parameter when extracting words and phrases to highlight, which allows …

Patch available
Fix from $1,950 2004-11-12
Phpbb MEDIUM 6.8
CVE-2004-0730

Multiple cross-site scripting (XSS) vulnerabilities in PhpBB 2.0.8 allow remote attackers to inject arbitrary web script or HTML via (1) the cat_titl…

Mitigation only
Fix from $1,600 2004-07-27
Phpbb MEDIUM 5.0
CVE-2004-0729

PhpBB 2.0.8 allows remote attackers to gain sensitive information via an invalid (1) category_rows parameter to index.php, (2) faq parameter to faq.p…

Mitigation only
Fix from $1,600 2004-07-27
Phpbb HIGH 7.5
CVE-2004-1943

PHP remote file inclusion vulnerability in album_portal.php in phpBB modified by Przemo 1.8 allows remote attackers to execute arbitrary PHP code via…

Patch available
Fix from $1,950 2004-04-19
Phpbb MEDIUM 5.0
CVE-2004-1950

phpBB 2.0.8a and earlier trusts the IP address that is in the X-Forwarded-For in the HTTP header, which allows remote attackers to spoof IP addresses.

Patch available
Fix from $1,600 2004-04-19
Phpbb HIGH 7.5
CVE-2003-1244

SQL injection vulnerability in page_header.php in phpBB 2.0, 2.0.1 and 2.0.2 allows remote attackers to brute force user passwords and possibly gain …

Patch available
Fix from $1,950 2003-12-31
Phpbb MEDIUM 6.8
CVE-2003-1373

Directory traversal vulnerability in auth.php for PhpBB 1.4.0 through 1.4.4 allows remote attackers to read and include arbitrary files via .. (dot d…

Mitigation only
Fix from $1,600 2003-12-31
Phpbb HIGH 7.5
CVE-2003-1216

SQL injection vulnerability in search.php for phpBB 2.0.6 and earlier allows remote attackers to execute arbitrary SQL and gain privileges via the se…

Patch available
Fix from $1,950 2003-11-27
Phpbb MEDIUM 6.8
CVE-2003-0484

Cross-site scripting (XSS) vulnerability in viewtopic.php for phpBB allows remote attackers to insert arbitrary web script via the topic_id parameter.

Mitigation only
Fix from $1,600 2003-08-07