Vulnerability index

Browse CVEs

9 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Usebb CRITICAL 9.8
CVE-2020-8088

panel_login.php in UseBB 1.0.12 allows type juggling for login bypass because != is used instead of !== for password hashes, which mishandles hashes …

No fix yet
Fix from $2,300 2020-01-27
Usebb HIGH 8.8
CVE-2011-3612

Cross-Site Request Forgery (CSRF) vulnerability exists in panel.php in UseBB before 1.0.12.

Fix: 1.0.12+
Fix from $1,950 2020-01-22
Usebb HIGH 7.2
CVE-2011-3611

A File Inclusion vulnerability exists in act parameter to admin.php in UseBB before 1.0.12.

Fix: 1.0.12+
Fix from $1,950 2020-01-22
Usebb MEDIUM 5.0
CVE-2009-4041

UseBB 1.0.9 before 1.0.10 allows remote attackers to cause a denial of service (infinite loop) via crafted BBCode tags.

Patch available
Fix from $1,600 2009-11-20
Usebb HIGH 9.3
CVE-2007-3963

Multiple cross-site scripting (XSS) vulnerabilities in UseBB 1.0.7, and possibly other 1.0.x versions, allow remote attackers to inject arbitrary web…

Mitigation only
Fix from $1,950 2007-07-25
Usebb MEDIUM 5.0
CVE-2007-2066

UseBB before 1.0.6 allows remote attackers to obtain sensitive information via a request with unspecified GET or POST parameters to an unspecified sc…

Mitigation only
Fix from $1,600 2007-04-18
Usebb MEDIUM 6.8
CVE-2006-2524

Cross-site scripting (XSS) vulnerability in UseBB 1.0 RC1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified …

Patch available
Fix from $1,600 2006-05-22
Usebb MEDIUM 6.4
CVE-2006-2525

SQL injection vulnerability in UseBB 1.0 RC1 and earlier allows remote attackers to execute arbitrary SQL commands via the member list search module.

Patch available
Fix from $1,600 2006-05-22
Usebb HIGH 7.5
CVE-2005-2439

SQL injection vulnerability in UseBB 0.5.1 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands …

Patch available
Fix from $1,950 2005-08-03