Vulnerability index

Browse CVEs

16 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ubb.threads HIGH 7.5
CVE-2008-6970EPSS 7%

SQL injection vulnerability in dosearch.inc.php in UBB.threads 7.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the Fo…

Fix: after 7.3.1
Fix from $1,950 2009-08-13
Ubb.threads HIGH 7.5
CVE-2007-1956

SQL injection vulnerability in ubbthreads.php in Groupee UBB.threads 6.1.1 and earlier allows remote attackers to execute arbitrary SQL commands via …

Fix: after 6.1.1
Fix from $1,950 2007-04-11
Ubb.threads HIGH 7.5
CVE-2006-5136

Multiple PHP remote file inclusion vulnerabilities in ubbt.inc.php in Groupee UBB.threads 6.5.1.1 allow remote attackers to execute arbitrary PHP cod…

No fix yet
Fix from $1,950 2006-10-03
Ubb.threads MEDIUM 5.1
CVE-2006-5137

Multiple direct static code injection vulnerabilities in Groupee UBB.threads 6.5.1.1 allow remote attackers to (1) inject PHP code via a theme[] arra…

No fix yet
Fix from $1,600 2006-10-03
Ubb.threads MEDIUM 5.0
CVE-2006-5138

Groupee UBB.threads 6.5.1.1 allows remote attackers to obtain sensitive information via a direct request for cron/php/subscriptions.php, which reveal…

No fix yet
Fix from $1,600 2006-10-03
Ubb.threads MEDIUM 5.1
CVE-2006-2675

PHP remote file inclusion vulnerability in ubbt.inc.php in UBBThreads 5.x and 6.x allows remote attackers to execute arbitrary PHP code via a URL in …

Fix: after 6.5.3
Fix from $1,600 2006-05-30
Ubb.threads MEDIUM 5.1
CVE-2006-2568EPSS 8%

PHP remote file inclusion vulnerability in addpost_newpoll.php in UBB.threads 6.4 through 6.5.2 and 6.5.1.1 (trial) allows remote attackers to execut…

No fix yet
Fix from $1,600 2006-05-24
Ubb.threads MEDIUM 5.0
CVE-2006-1423

SQL injection vulnerability in showflat.php in UBB.threads 5.5.1, 6.0 br5, 6.0.1, 6.0.2, and earlier, allows remote attackers to execute arbitrary SQ…

Mitigation only
Fix from $1,600 2006-03-28
Ubb.threads HIGH 7.5
CVE-2006-0545

SQL injection vulnerability in showflat.php in Groupee (formerly known as Infopop) UBB.threads 6.3 and earlier allows remote attackers to execute arb…

No fix yet
Fix from $1,950 2006-02-04
Ubb.threads HIGH 7.5
CVE-2005-2058

Multiple SQL injection vulnerabilities in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to execute arbitrary SQL commands via the Numb…

Patch available
Fix from $1,950 2005-06-29
Ubb.threads MEDIUM 6.8
CVE-2005-2057

Multiple cross-site scripting (XSS) vulnerabilities in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to inject arbitrary web script or…

Patch available
Fix from $1,600 2005-06-29
Ubb.threads MEDIUM 6.5
CVE-2005-2059

Multiple cross-site request forgery (CSRF) vulnerabilities in (1) addaddress.php, (2) toggleignore.php, (3) removeignore.php, and (4) removeaddress.p…

Fix: after 6.5.1.1
Fix from $1,600 2005-06-29
Ubb.threads MEDIUM 5.0
CVE-2005-2060

Multiple HTTP Response Splitting vulnerabilities in (1) toggleshow.php, (2) togglecats.php, and (3) showprofile.php in Infopop UBB.Threads before 6.5…

Patch available
Fix from $1,600 2005-06-29
Ubb.threads MEDIUM 5.0
CVE-2005-2061

Infopop UBB.Threads before 6.5.2 Beta allows remote attackers to include arbitrary files via the language parameter in a cookie followed by a null (%…

Patch available
Fix from $1,600 2005-06-29
Ubb.threads HIGH 7.5
CVE-2005-0726

SQL injection vulnerability in editpost.php in UBB.threads 6.0 allows remote attackers to execute arbitrary SQL commands via the Number parameter.

Mitigation only
Fix from $1,950 2005-05-02
Ubb.threads HIGH 7.5
CVE-2004-1622

SQL injection vulnerability in dosearch.php in UBB.threads 3.4.x allows remote attackers to execute arbitrary SQL statements via the Name parameter.

No fix yet
Fix from $1,950 2004-10-21