Vulnerability index

Browse CVEs

31 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Phpbb HIGH 10.0
CVE-2007-1695

PHP remote file inclusion vulnerability in includes/usercp_register.php in phpBB 2.0.19 allows remote attackers to execute arbitrary PHP code via a U…

Mitigation only
Fix from $1,950 2007-03-27
Phpbb MEDIUM 5.0
CVE-2006-2219

phpBB 2.0.20 does not verify user-specified input variable types before being passed to type-dependent functions, which allows remote attackers to ob…

Mitigation only
Fix from $1,600 2007-02-08
Phpbb MEDIUM 6.0
CVE-2006-6508

Cross-site request forgery (CSRF) vulnerability in phpBB 2.0.21 allows remote authenticated users to send unauthorized messages as an arbitrary user …

Mitigation only
Fix from $1,600 2006-12-14
Phpbb MEDIUM 6.0
CVE-2006-6421EPSS 15%

Cross-site scripting (XSS) vulnerability in the private message box implementation (privmsg.php) in phpBB 2.0.x allows remote authenticated users to …

Mitigation only
Fix from $1,600 2006-12-10
Phpbb HIGH 7.5
CVE-2006-5209

PHP remote file inclusion vulnerability in admin/admin_topic_action_logging.php in Admin Topic Action Logging Mod 0.95 and earlier, as used in phpBB …

No fix yet
Fix from $1,950 2006-10-10
Phpbb Auction HIGH 7.5
CVE-2006-3940

Multiple SQL injection vulnerabilities in phpbb-Auction allow remote attackers to execute arbitrary SQL commands via (1) the ar parameter in auction_…

No fix yet
Fix from $1,950 2006-07-31
Phpbb HIGH 7.5
CVE-2006-2865

PHP remote file inclusion vulnerability in template.php in phpBB 2 allows remote attackers to execute arbitrary PHP code via a URL in the page parame…

No fix yet
Fix from $1,950 2006-06-06
Phpbb HIGH 7.5
CVE-2006-2360

SQL injection vulnerability in charts.php in the Chart mod for phpBB allows remote attackers to execute arbitrary SQL commands via the id parameter.

Mitigation only
Fix from $1,950 2006-05-15
Phpbb Auction MEDIUM 6.8
CVE-2006-2245EPSS 8%

PHP remote file inclusion vulnerability in auction\auction_common.php in Auction mod 1.3m for phpBB allows remote attackers to execute arbitrary PHP …

Mitigation only
Fix from $1,600 2006-05-09
Phpbb Toplist MEDIUM 6.4
CVE-2006-2150

PHP remote file inclusion vulnerability in top/list.php in phpBB TopList 1.3.8 and earlier allows remote attackers to include arbitrary files via the…

Mitigation only
Fix from $1,600 2006-05-03
Phpbb MEDIUM 6.5
CVE-2006-1895

Direct static code injection vulnerability in includes/template.php in phpBB allows remote authenticated users with write access to execute arbitrary…

No fix yet
Fix from $1,600 2006-04-20
Phpbb MEDIUM 6.4
CVE-2006-0632

The gen_rand_string function in phpBB 2.0.19 uses insufficiently random data (small value space) to create the activation key ("validation ID") that …

No fix yet
Fix from $1,600 2006-02-10
Phpbb MEDIUM 5.0
CVE-2006-0438

Cross-site request forgery (CSRF) vulnerability in phpBB 2.0.19, when Link to off-site Avatar or bbcode (IMG) are enabled, allows remote attackers to…

No fix yet
Fix from $1,600 2006-02-06
Phpbb MEDIUM 5.0
CVE-2006-0450EPSS 5%

phpBB 2.0.19 and earlier allows remote attackers to cause a denial of service (application crash) by (1) registering many users through profile.php o…

No fix yet
Fix from $1,600 2006-01-27
Phpbb MEDIUM 5.0
CVE-2005-4358

admin/admin_disallow.php in phpBB 2.0.18 allows remote attackers to obtain the installation path via a direct request with a non-empty setmodules par…

Mitigation only
Fix from $1,600 2005-12-20
Phpbb MEDIUM 5.0
CVE-2005-3799

phpBB 2.0.18 allows remote attackers to obtain sensitive information via a large SQL query, which generates an error message that reveals SQL syntax …

No fix yet
Fix from $1,600 2005-11-24
Phpbb HIGH 7.5
CVE-2005-0614EPSS 8%

sessions.php in phpBB 2.0.12 and earlier allows remote attackers to gain administrator privileges via the autologinid value in a cookie.

Mitigation only
Fix from $1,950 2005-05-02
Phpbb HIGH 7.5
CVE-2005-1114

Multiple SQL injection vulnerabilities in album_search.php in Photo Album 2.0.53 for phpBB allow remote attackers to execute arbitrary SQL commands v…

No fix yet
Fix from $1,950 2005-05-02
Phpbb HIGH 7.5
CVE-2005-1196

SQL injection vulnerability in kb.php in the Knowledge Base module for phpBB allows remote attackers to obtain sensitive information and execute SQL …

Mitigation only
Fix from $1,950 2005-05-02
Phpbb MEDIUM 5.0
CVE-2005-0659

phpBB 2.0.13 and earlier allows remote attackers to obtain sensitive information via a direct request to oracle.php, which reveals the path in a PHP …

No fix yet
Fix from $1,600 2005-05-02
Phpbb MEDIUM 5.0
CVE-2005-0871

calendar_scheduler.php in Topic Calendar 1.0.1 module for phpBB, when running on a Microsoft IIS server, allows remote attackers to obtain sensitive …

No fix yet
Fix from $1,600 2005-05-02
Phpbb HIGH 7.5
CVE-2005-1047

Meilad File upload script (up.php) mod for phpBB 2.0.x does not properly limit the types of files that can be uploaded, which allows remote authentic…

Mitigation only
Fix from $1,950 2005-04-07
Phpbb HIGH 7.5
CVE-2004-1535EPSS 6%

PHP remote file inclusion vulnerability in admin_cash.php for the Cash Mod module for phpBB allows remote attackers to execute arbitrary PHP code by …

Mitigation only
Fix from $1,950 2004-12-31
Phpbb MEDIUM 5.0
CVE-2004-2054

CRLF injection vulnerability in PhpBB 2.0.4 and 2.0.9 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML cont…

No fix yet
Fix from $1,600 2004-12-31
Phpbb MEDIUM 6.8
CVE-2004-0730

Multiple cross-site scripting (XSS) vulnerabilities in PhpBB 2.0.8 allow remote attackers to inject arbitrary web script or HTML via (1) the cat_titl…

Mitigation only
Fix from $1,600 2004-07-27
Phpbb MEDIUM 5.0
CVE-2004-0729

PhpBB 2.0.8 allows remote attackers to gain sensitive information via an invalid (1) category_rows parameter to index.php, (2) faq parameter to faq.p…

Mitigation only
Fix from $1,600 2004-07-27
Phpbb MEDIUM 6.8
CVE-2003-1373

Directory traversal vulnerability in auth.php for PhpBB 1.4.0 through 1.4.4 allows remote attackers to read and include arbitrary files via .. (dot d…

Mitigation only
Fix from $1,600 2003-12-31
Phpbb MEDIUM 6.8
CVE-2003-0484

Cross-site scripting (XSS) vulnerability in viewtopic.php for phpBB allows remote attackers to insert arbitrary web script via the topic_id parameter.

Mitigation only
Fix from $1,600 2003-08-07
Phpbb MEDIUM 5.0
CVE-2002-1707

install.php in phpBB 2.0 through 2.0.1, when "allow_url_fopen" and "register_globals" variables are set to "on", allows remote attackers to execute a…

Mitigation only
Fix from $1,600 2002-12-31
Phpbb MEDIUM 5.1
CVE-2002-0475

Cross-site scripting vulnerability in phpBB 1.4.4 and earlier allows remote attackers to execute arbitrary Javascript on web clients by embedding the…

Mitigation only
Fix from $1,600 2002-08-12