Vulnerability index

Browse CVEs

69 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Phpbb HIGH 10.0
CVE-2007-1695

PHP remote file inclusion vulnerability in includes/usercp_register.php in phpBB 2.0.19 allows remote attackers to execute arbitrary PHP code via a U…

Mitigation only
Fix from $1,950 2007-03-27
Phpbb Advanced Guestbook MEDIUM 6.8
CVE-2006-7077

SQL injection vulnerability in guestbook.php in Advanced Guestbook 2.4 for phpBB allows remote attackers to execute arbitrary SQl commands via the en…

Patch available
Fix from $1,600 2007-03-02
Phpbb MEDIUM 5.0
CVE-2006-2219

phpBB 2.0.20 does not verify user-specified input variable types before being passed to type-dependent functions, which allows remote attackers to ob…

Mitigation only
Fix from $1,600 2007-02-08
Phpbb HIGH 10.0
CVE-2006-6839

Unspecified vulnerability in phpBB before 2.0.22 has unknown impact and remote attack vectors related to "criteria for 'bad' redirection targets."

Patch available
Fix from $1,950 2006-12-31
Phpbb HIGH 10.0
CVE-2006-6840

Unspecified vulnerability in phpBB before 2.0.22 has unknown impact and remote attack vectors related to a "negative start parameter."

Patch available
Fix from $1,950 2006-12-31
Phpbb HIGH 10.0
CVE-2006-6841

Certain forms in phpBB before 2.0.22 lack session checks, which has unknown impact and remote attack vectors.

Patch available
Fix from $1,950 2006-12-31
Phpbb MEDIUM 6.0
CVE-2006-6508

Cross-site request forgery (CSRF) vulnerability in phpBB 2.0.21 allows remote authenticated users to send unauthorized messages as an arbitrary user …

Mitigation only
Fix from $1,600 2006-12-14
Phpbb MEDIUM 6.0
CVE-2006-6421EPSS 15%

Cross-site scripting (XSS) vulnerability in the private message box implementation (privmsg.php) in phpBB 2.0.x allows remote authenticated users to …

Mitigation only
Fix from $1,600 2006-12-10
Phpbb HIGH 7.5
CVE-2006-5435

PHP remote file inclusion vulnerability in groupcp.php in phpBB 2.0.10 and earlier allows remote attackers to execute arbitrary PHP code via a URL in…

Fix: after 2.0.10
Fix from $1,950 2006-10-20
Phpbb HIGH 7.5
CVE-2006-5209

PHP remote file inclusion vulnerability in admin/admin_topic_action_logging.php in Admin Topic Action Logging Mod 0.95 and earlier, as used in phpBB …

No fix yet
Fix from $1,950 2006-10-10
Vitrax Premodded Phpbb HIGH 7.5
CVE-2006-4779

PHP remote file inclusion vulnerability in includes/functions_portal.php in Vitrax Premodded phpBB 1.0.6-R3 and earlier allows remote attackers to ex…

Fix: after 1.0.6_r3
Fix from $1,950 2006-09-14
Phpbb MEDIUM 5.1
CVE-2006-4450

usercp_avatar.php in PHPBB 2.0.20, when avatar uploading is enabled, allows remote attackers to use the server as a web proxy by submitting a URL to …

Patch available
Fix from $1,600 2006-08-30
Phpbb Auction HIGH 7.5
CVE-2006-3940

Multiple SQL injection vulnerabilities in phpbb-Auction allow remote attackers to execute arbitrary SQL commands via (1) the ar parameter in auction_…

No fix yet
Fix from $1,950 2006-07-31
Phpbb HIGH 7.5
CVE-2006-2865

PHP remote file inclusion vulnerability in template.php in phpBB 2 allows remote attackers to execute arbitrary PHP code via a URL in the page parame…

No fix yet
Fix from $1,950 2006-06-06
Phpbb HIGH 7.5
CVE-2006-2360

SQL injection vulnerability in charts.php in the Chart mod for phpBB allows remote attackers to execute arbitrary SQL commands via the id parameter.

Mitigation only
Fix from $1,950 2006-05-15
Phpbb Auction MEDIUM 6.8
CVE-2006-2245EPSS 8%

PHP remote file inclusion vulnerability in auction\auction_common.php in Auction mod 1.3m for phpBB allows remote attackers to execute arbitrary PHP …

Mitigation only
Fix from $1,600 2006-05-09
Phpbb Toplist HIGH 7.5
CVE-2006-2151EPSS 11%

PHP remote file inclusion vulnerability in toplist.php in phpBB TopList 1.3.8 and earlier, when register_globals is enabled, allows remote attackers …

Fix: after 1.3.8
Fix from $1,950 2006-05-03
Phpbb Advanced Guestbook HIGH 7.5
CVE-2006-2152EPSS 8%

PHP remote file inclusion vulnerability in admin/addentry.php in phpBB Advanced Guestbook 2.4.0 and earlier, when register_globals is enabled, allows…

Fix: after 2.4.0
Fix from $1,950 2006-05-03
Phpbb Toplist MEDIUM 6.4
CVE-2006-2150

PHP remote file inclusion vulnerability in top/list.php in phpBB TopList 1.3.8 and earlier allows remote attackers to include arbitrary files via the…

Mitigation only
Fix from $1,600 2006-05-03
Phpbb MEDIUM 5.1
CVE-2006-2134EPSS 9%

PHP remote file inclusion vulnerability in /includes/kb_constants.php in Knowledge Base Mod for PHPbb 2.0.2 and earlier allows remote attackers to ex…

Fix: after 2.0.2
Fix from $1,600 2006-05-02
Phpbb MEDIUM 6.5
CVE-2006-1895

Direct static code injection vulnerability in includes/template.php in phpBB allows remote authenticated users with write access to execute arbitrary…

No fix yet
Fix from $1,600 2006-04-20
Phpbb MEDIUM 6.0
CVE-2006-1896

Unspecified vulnerability in phpBB allows remote authenticated users with Administration Panel access to execute arbitrary PHP code via crafted Font …

Patch available
Fix from $1,600 2006-04-20
Phpbb MEDIUM 6.4
CVE-2006-0632

The gen_rand_string function in phpBB 2.0.19 uses insufficiently random data (small value space) to create the activation key ("validation ID") that …

No fix yet
Fix from $1,600 2006-02-10
Phpbb MEDIUM 5.0
CVE-2006-0438

Cross-site request forgery (CSRF) vulnerability in phpBB 2.0.19, when Link to off-site Avatar or bbcode (IMG) are enabled, allows remote attackers to…

No fix yet
Fix from $1,600 2006-02-06
Phpbb MEDIUM 5.0
CVE-2006-0450EPSS 5%

phpBB 2.0.19 and earlier allows remote attackers to cause a denial of service (application crash) by (1) registering many users through profile.php o…

No fix yet
Fix from $1,600 2006-01-27
Phpbb HIGH 7.5
CVE-2005-3536

SQL injection vulnerability in phpBB 2 before 2.0.18 allows remote attackers to execute arbitrary SQL commands via the topic type.

Patch available
Fix from $1,950 2005-12-22
Phpbb MEDIUM 5.0
CVE-2005-3537

A "missing request validation" error in phpBB 2 before 2.0.18 allows remote attackers to edit private messages of other users, probably by modifying …

Patch available
Fix from $1,600 2005-12-22
Phpbb MEDIUM 5.0
CVE-2005-4358

admin/admin_disallow.php in phpBB 2.0.18 allows remote attackers to obtain the installation path via a direct request with a non-empty setmodules par…

Mitigation only
Fix from $1,600 2005-12-20
Phpbb MEDIUM 5.0
CVE-2005-3799

phpBB 2.0.18 allows remote attackers to obtain sensitive information via a large SQL query, which generates an error message that reveals SQL syntax …

No fix yet
Fix from $1,600 2005-11-24
Phpbb HIGH 7.5
CVE-2005-3415

phpBB 2.0.17 and earlier allows remote attackers to bypass protection mechanisms that deregister global variables by setting both a GET/POST/COOKIE (…

Patch available
Fix from $1,950 2005-11-01