Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
phpbb vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2008-4125
The search function in phpBB 2.x provides a search_id value that leaks the state of PHP's PRNG, which allows remote malicious users to obtain potentially sensitive information, as demonstrated by a cross-application attack against WordPress, a different vulnerability than CV...
Phpbb Phpbb 2
NA
CVE-2008-7143
phpBB 2.0.23 includes the session ID in a request to modcp.php when the moderator or administrator closes a thread, which allows remote malicious users to hijack the session via a post in the thread containing a URL to a remotely hosted image, which might include the session ID i...
Phpbb Phpbb 2.0.23
NA
CVE-2006-2220
phpBB 2.0.20 does not properly verify user-specified input variables used as limits to SQL queries, which allows remote malicious users to obtain sensitive information via a negative LIMIT specification, as demonstrated by the start parameter to memberlist.php, which reveals the ...
Phpbb Phpbb 2.0.20
NA
CVE-2002-2255
Cross-site scripting (XSS) vulnerability in search.php in phpBB 2.0.3 and possibly earlier versions allows remote malicious users to inject arbitrary web script or HTML via the search_username parameter in searchuser mode.
Phpbb Phpbb 2.0.3
1 EDB exploit
NA
CVE-2006-2360
SQL injection vulnerability in charts.php in the Chart mod for phpBB allows remote malicious users to execute arbitrary SQL commands via the id parameter.
Phpbb Group Phpbb
1 EDB exploit
NA
CVE-2006-1896
Unspecified vulnerability in phpBB allows remote authenticated users with Administration Panel access to execute arbitrary PHP code via crafted Font Colour 3 ($theme[fontcolor3] variable) and/or signature values, possibly involving the highlight functionality. NOTE: the original ...
Phpbb Group Phpbb
NA
CVE-2006-2359
Cross-site scripting (XSS) vulnerability in charts.php in the Chart mod for phpBB allows remote malicious users to inject arbitrary web script or HTML via the id parameter. NOTE: this issue might be resultant from SQL injection.
Phpbb Group Phpbb
1 EDB exploit
NA
CVE-2010-1627
feed.php in phpBB 3.0.7 prior to 3.0.7-PL1 does not properly check permissions for feeds, which allows remote malicious users to bypass intended access restrictions via unspecified attack vectors related to permission settings on a private forum.
Phpbb Phpbb 3.0.7
NA
CVE-2003-1530
SQL injection vulnerability in privmsg.php in phpBB 2.0.3 and previous versions allows remote malicious users to execute arbitrary SQL commands via the mark[] parameter.
Phpbb Phpbb 2.0.3
1 EDB exploit
NA
CVE-2002-1537
admin_ug_auth.php in phpBB 2.0.0 allows local users to gain administrator privileges by directly calling admin_ug_auth.php with modifed form fields such as "u".
Phpbb Group Phpbb 2.0.0
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-5248
CVE-2024-3110
CVE-2024-5552
CVE-2024-29415
HTML injection
CVE-2024-3095
TCP
type confusion
CVE-2024-1800
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
6
7
8
9
10
NEXT »