Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
ralph capper tinyphpforum 3.6 vulnerabilities and exploits
(subscribe to this query)
5
CVSSv2
CVE-2006-0104
Directory traversal vulnerability in TinyPHPForum 3.6 and previous versions allows remote malicious users to create a new user account, create a new topic, or view the profile of a user account, as demonstrated via a .. (dot dot) in the uname parameter to profile.php.
Ralph Capper Tinyphpforum 3.47
Ralph Capper Tinyphpforum 3.48
Ralph Capper Tinyphpforum 3.49
Ralph Capper Tinyphpforum 3.499
Ralph Capper Tinyphpforum 3.46
Ralph Capper Tinyphpforum 3.5
Ralph Capper Tinyphpforum 3.6
4.3
CVSSv2
CVE-2006-0102
Cross-site scripting (XSS) vulnerability in TinyPHPForum (TPF) 3.6 and previous versions allows remote malicious users to inject arbitrary web script via a javascript: scheme in an "[a]" bbcode tag, possibly the txt parameter to action.php.
Ralph Capper Tinyphpforum 3.46
Ralph Capper Tinyphpforum 3.47
Ralph Capper Tinyphpforum 3.48
Ralph Capper Tinyphpforum 3.49
Ralph Capper Tinyphpforum 3.499
Ralph Capper Tinyphpforum 3.5
Ralph Capper Tinyphpforum 3.6
5
CVSSv2
CVE-2006-0103
TinyPHPForum 3.6 and previous versions stores the (1) users/[USERNAME].hash and (2) users/[USERNAME].email files under the web root with insufficient access control, which allows remote malicious users to list all registered users and possibly obtain other sensitive information.
Ralph Capper Tinyphpforum 3.47
Ralph Capper Tinyphpforum 3.48
Ralph Capper Tinyphpforum 3.49
Ralph Capper Tinyphpforum 3.499
Ralph Capper Tinyphpforum 3.46
Ralph Capper Tinyphpforum 3.5
Ralph Capper Tinyphpforum 3.6
1 EDB exploit
2.6
CVSSv2
CVE-2006-1898
Multiple cross-site scripting (XSS) vulnerabilities in Ralph Capper Tiny PHP Forum (TPF) 3.6 allow remote malicious users to inject arbitrary web script or HTML via (1) the uname parameter in a view action in profile.php and (2) a login name. NOTE: the "Access to hash passwo...
Ralph Capper Tinyphpforum 3.6
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2020-4463
CVE-2024-3400
deserialization
CVE-2024-21788
CVE-2023-42433
CVE-2024-21841
CVE-2024-22095
local file inclusion
memory leak
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started