Vulnerability index

Browse CVEs

23 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Punbb MEDIUM 6.8
CVE-2008-7241

Cross-site request forgery (CSRF) vulnerability in PunBB before 1.2.17 allows remote attackers to hijack the authentication of unspecified users for …

Fix: after 1.2.16
Fix from $1,600 2009-09-17
Private Messaging System MEDIUM 5.1
CVE-2008-6308

Multiple directory traversal vulnerabilities in Private Messaging System (PMS) 1.2.3 and earlier for PunBB allow remote attackers to include and exec…

Fix: after 1.2.3
Fix from $1,600 2009-02-27
Punbb MEDIUM 6.5
CVE-2008-5434

Multiple SQL injection vulnerabilities in PunBB 1.3 and 1.3.1 allow remote authenticated administrators to execute arbitrary SQL commands via the (1)…

Mitigation only
Fix from $1,600 2008-12-11
Punbb HIGH 10.0
CVE-2008-3335

Unspecified vulnerability in PunBB before 1.2.19 allows remote attackers to inject arbitrary SMTP commands via unknown vectors.

Fix: after 1.2.18
Fix from $1,950 2008-07-27
Punbb HIGH 7.5
CVE-2007-2234

include/common.php in PunBB 1.2.14 and earlier does not properly handle a disabled ini_get function when checking the register_globals setting, which…

Fix: after 1.2.14
Fix from $1,950 2007-04-25
Punbb MEDIUM 6.8
CVE-2007-2236

footer.php in PunBB 1.2.14 and earlier allows remote attackers to include local files in include/user/ via a cross-site scripting (XSS) attack, or vi…

Fix: after 1.2.14
Fix from $1,600 2007-04-25
Punbb HIGH 7.5
CVE-2006-5735EPSS 14%

Directory traversal vulnerability in include/common.php in PunBB before 1.2.14 allows remote authenticated users to include and execute arbitrary loc…

Fix: after 1.2.13
Fix from $1,950 2006-11-06
Punbb HIGH 7.2
CVE-2006-5737

PunBB uses a predictable cookie_seed value that can be derived from the time of registration of the superadmin account (installation time), which mig…

Mitigation only
Fix from $1,950 2006-11-06
Punbb HIGH 7.2
CVE-2006-5738

Multiple SQL injection vulnerabilities in PunBB before 1.2.14 allow remote authenticated administrators to execute arbitrary SQL commands via unspeci…

Fix: after 1.2.13
Fix from $1,950 2006-11-06
Punbb MEDIUM 5.1
CVE-2006-5736

SQL injection vulnerability in search.php in PunBB before 1.2.14, when the PHP installation is vulnerable to CVE-2006-3017, allows remote attackers t…

Fix: after 1.2.13
Fix from $1,600 2006-11-06
Punbb MEDIUM 6.8
CVE-2006-2724

Cross-site scripting (XSS) vulnerability in PunBB 1.2.11 allows remote authenticated administrators to inject arbitrary HTML or web script to other a…

Mitigation only
Fix from $1,600 2006-06-01
Punbb HIGH 7.8
CVE-2006-1090

register.php in PunBB 1.2.10 allows remote attackers to cause an unspecified denial of service via a flood of new user registrations.

Patch available
Fix from $1,950 2006-03-09
Punbb MEDIUM 5.0
CVE-2006-0865

PunBB 1.2.10 and earlier allows remote attackers to cause a denial of service (resource consumption) by registering many user accounts quickly.

No fix yet
Fix from $1,600 2006-02-23
Punbb MEDIUM 5.0
CVE-2006-0866

PunBB 1.2.10 and earlier allows remote attackers to conduct brute force guessing attacks for an account's password, which may be as short as 4 charac…

Mitigation only
Fix from $1,600 2006-02-23
Punbb MEDIUM 5.0
CVE-2005-4686

PunBB 1.2.9, when used alone or with F-ART BLOG:CMS, includes config.php before calling the unregister_globals function, which allows attackers to ob…

Patch available
Fix from $1,600 2005-12-31
Punbb MEDIUM 5.0
CVE-2005-4688

PunBB 1.2.9 does not require password entry when changing the e-mail address in an account's profile, which might allow an attacker to make an addres…

Mitigation only
Fix from $1,600 2005-12-31
Punbb HIGH 7.5
CVE-2005-3518

SQL injection vulnerability in search.php in PunBB 1.2.7 and 1.2.8 allows remote attackers to execute arbitrary SQL commands via the old_searches par…

Patch available
Fix from $1,950 2005-11-06
Punbb HIGH 7.5
CVE-2005-3328

PHP remote file inclusion vulnerability in common.php in PunBB 1.1.2 through 1.1.5 allows remote attackers to execute arbitrary code via the pun_root…

Mitigation only
Fix from $1,950 2005-10-27
Punbb HIGH 7.5
CVE-2005-2193

SQL injection vulnerability in the user profile edit module in profile.php for PunBB 1.2.5 and earlier allows remote attackers to execute arbitrary S…

Patch available
Fix from $1,950 2005-07-11
Punbb HIGH 7.5
CVE-2005-0569

Multiple SQL injection vulnerabilities in PunBB 1.2.1 allow remote attackers to execute arbitrary SQL commands via the (1) language parameter to regi…

Patch available
Fix from $1,950 2005-05-02
Punbb MEDIUM 6.5
CVE-2005-1051

SQL injection vulnerability in profile.php in PunBB 1.2.4 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in…

Patch available
Fix from $1,600 2005-05-02
Punbb MEDIUM 5.0
CVE-2005-0570

profile.php in PunBB 1.2.1 allows remote attackers to cause a denial of service (account lockout) by setting the user's password to NULL.

Patch available
Fix from $1,600 2005-05-02
Punbb MEDIUM 5.0
CVE-2005-0571

admin_loader.php in PunBB 1.2.1 allows remote attackers to read arbitrary files via the plugin parameter.

Patch available
Fix from $1,600 2005-05-02