Vulnerability index

Browse CVEs

23 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Deluxebb MEDIUM 5.0
CVE-2011-3725

DeluxeBB 1.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an e…

No fix yet
Fix from $1,600 2011-09-23
Deluxebb MEDIUM 6.8
CVE-2010-4151

SQL injection vulnerability in misc.php in DeluxeBB 1.3, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute …

Fix: after 1.3
Fix from $1,600 2010-11-03
Deluxebb MEDIUM 6.8
CVE-2010-1859

SQL injection vulnerability in newpost.php in DeluxeBB 1.3 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitra…

Fix: after 1.3
Fix from $1,600 2010-05-07
Deluxebb HIGH 7.5
CVE-2009-4465

DeluxeBB 1.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain user and confi…

No fix yet
Fix from $1,950 2009-12-30
Deluxebb MEDIUM 5.0
CVE-2009-4466

DeluxeBB 1.3 allows remote attackers to obtain sensitive information via a crafted page parameter to misc.php, which reveals the installation path in…

No fix yet
Fix from $1,600 2009-12-30
Deluxebb HIGH 7.5
CVE-2009-1033

SQL injection vulnerability in misc.php in DeluxeBB 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the qorder paramete…

Fix: after 1.3
Fix from $1,950 2009-03-20
Deluxebb MEDIUM 6.8
CVE-2008-6146

SQL injection vulnerability in pm.php in DeluxeBB 1.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQ…

Fix: after 1.2
Fix from $1,600 2009-02-16
Deluxebb HIGH 7.5
CVE-2008-2194

SQL injection vulnerability in forums.php in DeluxeBB 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the sort paramete…

Fix: after 1.2
Fix from $1,950 2008-05-14
Deluxebb MEDIUM 6.5
CVE-2008-2195

Static code injection vulnerability in admincp.php in DeluxeBB 1.2 and earlier allows remote authenticated administrators to inject arbitrary PHP cod…

Fix: after 1.2
Fix from $1,600 2008-05-14
Deluxebb HIGH 9.0
CVE-2007-6237

cp.php in DeluxeBB 1.09 does not verify that the membercookie parameter corresponds to the authenticated member during a profile update, which allows…

Mitigation only
Fix from $1,950 2007-12-04
Deluxebb HIGH 7.5
CVE-2006-5154

PHP remote file inclusion vulnerability in cp/sig.php in DeluxeBB 1.09 and earlier allows remote attackers to execute arbitrary PHP code via a URL in…

Patch available
Fix from $1,950 2006-10-05
Deluxebb HIGH 7.5
CVE-2006-4558

DeluxeBB 1.06 and earlier, when run on the Apache HTTP Server with the mod_mime module, allows remote attackers to execute arbitrary PHP code by uplo…

Fix: after 1.06
Fix from $1,950 2006-09-06
Deluxebb HIGH 7.5
CVE-2006-4078

pm.php (aka the PM system) in DeluxeBB 1.08, and possibly earlier, allows remote attackers to bypass authentication by providing an arbitrary usernam…

Patch available
Fix from $1,950 2006-08-11
Deluxebb MEDIUM 6.8
CVE-2006-4079

Cross-site scripting (XSS) vulnerability in newpost.php in DeluxeBB 1.08, and possibly earlier, allows remote attackers to inject arbitrary web scrip…

Fix: after 1.08
Fix from $1,600 2006-08-11
Deluxebb HIGH 7.5
CVE-2006-3796

DeluxeBB 1.07 and earlier does not properly handle a username composed of a single space character, which allows remote authenticated users to login …

Fix: after 1.07
Fix from $1,950 2006-07-24
Deluxebb HIGH 7.5
CVE-2006-3797

SQL injection vulnerability in DeluxeBB 1.07 and earlier allows remote attackers to bypass authentication, spoof users, and modify settings via the (…

Mitigation only
Fix from $1,950 2006-07-24
Deluxebb HIGH 7.5
CVE-2006-3799

DeluxeBB 1.07 and earlier allows remote attackers to bypass SQL injection protection mechanisms via the login variable and certain other variables, b…

Patch available
Fix from $1,950 2006-07-24
Deluxebb MEDIUM 5.0
CVE-2006-3798

DeluxeBB 1.07 and earlier allows remote attackers to overwrite the (1) _GET, (2) _POST, (3) _ENV, and (4) _SERVER variables via the _COOKIE (aka COOK…

Mitigation only
Fix from $1,600 2006-07-24
Deluxebb HIGH 7.5
CVE-2006-3304

SQL injection vulnerability in cp.php in DeluxeBB 1.07 and earlier allows remote attackers to execute arbitrary SQL commands via the xmsn parameter.

Fix: after 1.07
Fix from $1,950 2006-06-29
Deluxebb MEDIUM 5.1
CVE-2006-2915

Multiple SQL injection vulnerabilities in DeluxeBB 1.06 allow remote attackers to execute arbitrary SQL commands via the (1) hideemail, (2) languagex…

Mitigation only
Fix from $1,600 2006-06-23
Deluxebb MEDIUM 5.1
CVE-2006-2914EPSS 21%

PHP remote file inclusion vulnerability in DeluxeBB 1.06 allows remote attackers to execute arbitrary code via a URL in the templatefolder parameter …

No fix yet
Fix from $1,600 2006-06-23
Deluxebb HIGH 7.5
CVE-2006-2503

SQL injection vulnerability in misc.php in DeluxeBB 1.06 allows remote attackers to execute arbitrary SQL commands via the name parameter.

No fix yet
Fix from $1,950 2006-05-22
Deluxebb HIGH 7.5
CVE-2005-2989

Multiple SQL injection vulnerabilities in DeluxeBB 1.0 and 1.0.5 allow remote attackers to execute arbitrary SQL commands via the (1) tid parameter t…

Patch available
Fix from $1,950 2005-09-20