Vulnerability index

Browse CVEs

69 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 10.0 CVE-2007-1695 PHP remote file inclusion vulnerability in includes/usercp_register.php in phpBB 2.0.19 allows remote attackers to execute arbitrary PHP code via a U… Phpbb Mitigation only Fix from $1,9502007-03-27 MEDIUM 6.8 CVE-2006-7077 SQL injection vulnerability in guestbook.php in Advanced Guestbook 2.4 for phpBB allows remote attackers to execute arbitrary SQl commands via the en… Phpbb Advanced Guestbook Patch available Fix from $1,6002007-03-02 MEDIUM 5.0 CVE-2006-2219 phpBB 2.0.20 does not verify user-specified input variable types before being passed to type-dependent functions, which allows remote attackers to ob… Phpbb Mitigation only Fix from $1,6002007-02-08 HIGH 10.0 CVE-2006-6839 Unspecified vulnerability in phpBB before 2.0.22 has unknown impact and remote attack vectors related to "criteria for 'bad' redirection targets." Phpbb Patch available Fix from $1,9502006-12-31 HIGH 10.0 CVE-2006-6840 Unspecified vulnerability in phpBB before 2.0.22 has unknown impact and remote attack vectors related to a "negative start parameter." Phpbb Patch available Fix from $1,9502006-12-31 HIGH 10.0 CVE-2006-6841 Certain forms in phpBB before 2.0.22 lack session checks, which has unknown impact and remote attack vectors. Phpbb Patch available Fix from $1,9502006-12-31 MEDIUM 6.0 CVE-2006-6508 Cross-site request forgery (CSRF) vulnerability in phpBB 2.0.21 allows remote authenticated users to send unauthorized messages as an arbitrary user … Phpbb Mitigation only Fix from $1,6002006-12-14 MEDIUM 6.0 CVE-2006-6421EPSS 15% Cross-site scripting (XSS) vulnerability in the private message box implementation (privmsg.php) in phpBB 2.0.x allows remote authenticated users to … Phpbb Mitigation only Fix from $1,6002006-12-10 HIGH 7.5 CVE-2006-5435 PHP remote file inclusion vulnerability in groupcp.php in phpBB 2.0.10 and earlier allows remote attackers to execute arbitrary PHP code via a URL in… Phpbb after 2.0.10 Fix from $1,9502006-10-20 HIGH 7.5 CVE-2006-5209 PHP remote file inclusion vulnerability in admin/admin_topic_action_logging.php in Admin Topic Action Logging Mod 0.95 and earlier, as used in phpBB … Phpbb No fix yet Fix from $1,9502006-10-10 HIGH 7.5 CVE-2006-4779 PHP remote file inclusion vulnerability in includes/functions_portal.php in Vitrax Premodded phpBB 1.0.6-R3 and earlier allows remote attackers to ex… Vitrax Premodded Phpbb after 1.0.6_r3 Fix from $1,9502006-09-14 MEDIUM 5.1 CVE-2006-4450 usercp_avatar.php in PHPBB 2.0.20, when avatar uploading is enabled, allows remote attackers to use the server as a web proxy by submitting a URL to … Phpbb Patch available Fix from $1,6002006-08-30 HIGH 7.5 CVE-2006-3940 Multiple SQL injection vulnerabilities in phpbb-Auction allow remote attackers to execute arbitrary SQL commands via (1) the ar parameter in auction_… Phpbb Auction No fix yet Fix from $1,9502006-07-31 HIGH 7.5 CVE-2006-2865 PHP remote file inclusion vulnerability in template.php in phpBB 2 allows remote attackers to execute arbitrary PHP code via a URL in the page parame… Phpbb No fix yet Fix from $1,9502006-06-06 HIGH 7.5 CVE-2006-2360 SQL injection vulnerability in charts.php in the Chart mod for phpBB allows remote attackers to execute arbitrary SQL commands via the id parameter. Phpbb Mitigation only Fix from $1,9502006-05-15 MEDIUM 6.8 CVE-2006-2245EPSS 8% PHP remote file inclusion vulnerability in auction\auction_common.php in Auction mod 1.3m for phpBB allows remote attackers to execute arbitrary PHP … Phpbb Auction Mitigation only Fix from $1,6002006-05-09 HIGH 7.5 CVE-2006-2151EPSS 11% PHP remote file inclusion vulnerability in toplist.php in phpBB TopList 1.3.8 and earlier, when register_globals is enabled, allows remote attackers … Phpbb Toplist after 1.3.8 Fix from $1,9502006-05-03 HIGH 7.5 CVE-2006-2152EPSS 8% PHP remote file inclusion vulnerability in admin/addentry.php in phpBB Advanced Guestbook 2.4.0 and earlier, when register_globals is enabled, allows… Phpbb Advanced Guestbook after 2.4.0 Fix from $1,9502006-05-03 MEDIUM 6.4 CVE-2006-2150 PHP remote file inclusion vulnerability in top/list.php in phpBB TopList 1.3.8 and earlier allows remote attackers to include arbitrary files via the… Phpbb Toplist Mitigation only Fix from $1,6002006-05-03 MEDIUM 5.1 CVE-2006-2134EPSS 9% PHP remote file inclusion vulnerability in /includes/kb_constants.php in Knowledge Base Mod for PHPbb 2.0.2 and earlier allows remote attackers to ex… Phpbb after 2.0.2 Fix from $1,6002006-05-02 MEDIUM 6.5 CVE-2006-1895 Direct static code injection vulnerability in includes/template.php in phpBB allows remote authenticated users with write access to execute arbitrary… Phpbb No fix yet Fix from $1,6002006-04-20 MEDIUM 6.0 CVE-2006-1896 Unspecified vulnerability in phpBB allows remote authenticated users with Administration Panel access to execute arbitrary PHP code via crafted Font … Phpbb Patch available Fix from $1,6002006-04-20 MEDIUM 6.4 CVE-2006-0632 The gen_rand_string function in phpBB 2.0.19 uses insufficiently random data (small value space) to create the activation key ("validation ID") that … Phpbb No fix yet Fix from $1,6002006-02-10 MEDIUM 5.0 CVE-2006-0438 Cross-site request forgery (CSRF) vulnerability in phpBB 2.0.19, when Link to off-site Avatar or bbcode (IMG) are enabled, allows remote attackers to… Phpbb No fix yet Fix from $1,6002006-02-06 MEDIUM 5.0 CVE-2006-0450EPSS 5% phpBB 2.0.19 and earlier allows remote attackers to cause a denial of service (application crash) by (1) registering many users through profile.php o… Phpbb No fix yet Fix from $1,6002006-01-27 HIGH 7.5 CVE-2005-3536 SQL injection vulnerability in phpBB 2 before 2.0.18 allows remote attackers to execute arbitrary SQL commands via the topic type. Phpbb Patch available Fix from $1,9502005-12-22 MEDIUM 5.0 CVE-2005-3537 A "missing request validation" error in phpBB 2 before 2.0.18 allows remote attackers to edit private messages of other users, probably by modifying … Phpbb Patch available Fix from $1,6002005-12-22 MEDIUM 5.0 CVE-2005-4358 admin/admin_disallow.php in phpBB 2.0.18 allows remote attackers to obtain the installation path via a direct request with a non-empty setmodules par… Phpbb Mitigation only Fix from $1,6002005-12-20 MEDIUM 5.0 CVE-2005-3799 phpBB 2.0.18 allows remote attackers to obtain sensitive information via a large SQL query, which generates an error message that reveals SQL syntax … Phpbb No fix yet Fix from $1,6002005-11-24 HIGH 7.5 CVE-2005-3415 phpBB 2.0.17 and earlier allows remote attackers to bypass protection mechanisms that deregister global variables by setting both a GET/POST/COOKIE (… Phpbb Patch available Fix from $1,9502005-11-01