Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
ralph capper tinyphpforum 3.6 vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2006-1898
Multiple cross-site scripting (XSS) vulnerabilities in Ralph Capper Tiny PHP Forum (TPF) 3.6 allow remote malicious users to inject arbitrary web script or HTML via (1) the uname parameter in a view action in profile.php and (2) a login name. NOTE: the "Access to hash passwo...
Ralph Capper Tinyphpforum 3.6
NA
CVE-2006-0104
Directory traversal vulnerability in TinyPHPForum 3.6 and previous versions allows remote malicious users to create a new user account, create a new topic, or view the profile of a user account, as demonstrated via a .. (dot dot) in the uname parameter to profile.php.
Ralph Capper Tinyphpforum 3.47
Ralph Capper Tinyphpforum 3.48
Ralph Capper Tinyphpforum 3.49
Ralph Capper Tinyphpforum 3.499
Ralph Capper Tinyphpforum 3.46
Ralph Capper Tinyphpforum 3.5
Ralph Capper Tinyphpforum 3.6
NA
CVE-2006-0102
Cross-site scripting (XSS) vulnerability in TinyPHPForum (TPF) 3.6 and previous versions allows remote malicious users to inject arbitrary web script via a javascript: scheme in an "[a]" bbcode tag, possibly the txt parameter to action.php.
Ralph Capper Tinyphpforum 3.46
Ralph Capper Tinyphpforum 3.47
Ralph Capper Tinyphpforum 3.48
Ralph Capper Tinyphpforum 3.49
Ralph Capper Tinyphpforum 3.499
Ralph Capper Tinyphpforum 3.5
Ralph Capper Tinyphpforum 3.6
NA
CVE-2006-0103
TinyPHPForum 3.6 and previous versions stores the (1) users/[USERNAME].hash and (2) users/[USERNAME].email files under the web root with insufficient access control, which allows remote malicious users to list all registered users and possibly obtain other sensitive information.
Ralph Capper Tinyphpforum 3.47
Ralph Capper Tinyphpforum 3.48
Ralph Capper Tinyphpforum 3.49
Ralph Capper Tinyphpforum 3.499
Ralph Capper Tinyphpforum 3.46
Ralph Capper Tinyphpforum 3.5
Ralph Capper Tinyphpforum 3.6
1 EDB exploit
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
denial of service
CVE-2024-27371
CVE-2024-20405
CVE-2024-31627
CVE-2024-31625
race condition
CVE-2024-4358
cross-site scripting
CVE-2023-20938
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started