Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
ralph capper tinyphpforum 3.47 vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv2
CVE-2006-0102
Cross-site scripting (XSS) vulnerability in TinyPHPForum (TPF) 3.6 and previous versions allows remote malicious users to inject arbitrary web script via a javascript: scheme in an "[a]" bbcode tag, possibly the txt parameter to action.php.
Ralph Capper Tinyphpforum 3.46
Ralph Capper Tinyphpforum 3.47
Ralph Capper Tinyphpforum 3.48
Ralph Capper Tinyphpforum 3.49
Ralph Capper Tinyphpforum 3.499
Ralph Capper Tinyphpforum 3.5
Ralph Capper Tinyphpforum 3.6
5
CVSSv2
CVE-2006-0103
TinyPHPForum 3.6 and previous versions stores the (1) users/[USERNAME].hash and (2) users/[USERNAME].email files under the web root with insufficient access control, which allows remote malicious users to list all registered users and possibly obtain other sensitive information.
Ralph Capper Tinyphpforum 3.47
Ralph Capper Tinyphpforum 3.48
Ralph Capper Tinyphpforum 3.49
Ralph Capper Tinyphpforum 3.499
Ralph Capper Tinyphpforum 3.46
Ralph Capper Tinyphpforum 3.5
Ralph Capper Tinyphpforum 3.6
1 EDB exploit
5
CVSSv2
CVE-2006-0104
Directory traversal vulnerability in TinyPHPForum 3.6 and previous versions allows remote malicious users to create a new user account, create a new topic, or view the profile of a user account, as demonstrated via a .. (dot dot) in the uname parameter to profile.php.
Ralph Capper Tinyphpforum 3.47
Ralph Capper Tinyphpforum 3.48
Ralph Capper Tinyphpforum 3.49
Ralph Capper Tinyphpforum 3.499
Ralph Capper Tinyphpforum 3.46
Ralph Capper Tinyphpforum 3.5
Ralph Capper Tinyphpforum 3.6
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
authentication bypass
CVE-2024-30043
camera
CVE-2023-40404
CVE-2024-2793
client side
CVE-2024-4469
CVE-2024-3565
CVE-2024-29825
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started