Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
deluxebb deluxebb vulnerabilities and exploits
(subscribe to this query)
435
VMScore
CVE-2008-0439
Cross-site scripting (XSS) vulnerability in templates/default/admincp/attachments_header.php in DeluxeBB 1.1 allows remote malicious users to inject arbitrary web script or HTML via the lang_listofmatches parameter.
Deluxebb Deluxebb 1.1
1 EDB exploit
515
VMScore
CVE-2006-2914
PHP remote file inclusion vulnerability in DeluxeBB 1.06 allows remote malicious users to execute arbitrary code via a URL in the templatefolder parameter to (1) postreply.php, (2) posting.php, (3) and pm/newpm.php in the deluxe/ directory, and (4) postreply.php, (5) posting.php,...
Deluxebb Deluxebb 1.06
1 EDB exploit
454
VMScore
CVE-2006-2915
Multiple SQL injection vulnerabilities in DeluxeBB 1.06 allow remote malicious users to execute arbitrary SQL commands via the (1) hideemail, (2) languagex, (3) xthetimeoffset, and (4) xthetimeformat parameters during account registration.
Deluxebb Deluxebb 1.06
445
VMScore
CVE-2011-3725
DeluxeBB 1.3 allows remote malicious users to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by header_html.php.
Deluxebb Deluxebb 1.3
755
VMScore
CVE-2009-4465
DeluxeBB 1.3 stores sensitive information under the web root with insufficient access control, which allows remote malicious users to obtain user and configuration information, log data, and gain administrative access via a direct request to scripts in (1) templates/ including (2...
Deluxebb Deluxebb 1.3
1 EDB exploit
505
VMScore
CVE-2009-4466
DeluxeBB 1.3 allows remote malicious users to obtain sensitive information via a crafted page parameter to misc.php, which reveals the installation path in an error message. NOTE: this issue might be resultant from improperly controlled computation in tools.php that leads to a de...
Deluxebb Deluxebb 1.3
1 EDB exploit
405
VMScore
CVE-2009-4467
misc.php in DeluxeBB 1.3 allows remote malicious users to register accounts without a valid email address via a valemail action with the valmem set to a pre-assigned user ID, which is visible from a memberlist action.
Deluxebb Deluxebb 1.3
1 EDB exploit
435
VMScore
CVE-2009-4468
Cross-site scripting (XSS) vulnerability in misc.php in DeluxeBB 1.3 allows remote malicious users to inject arbitrary web script or HTML via the page parameter.
Deluxebb Deluxebb 1.3
1 EDB exploit
755
VMScore
CVE-2006-2503
SQL injection vulnerability in misc.php in DeluxeBB 1.06 allows remote malicious users to execute arbitrary SQL commands via the name parameter.
Deluxebb Deluxebb 1.06
1 EDB exploit
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
TCP
CVE-2024-4577
CVE-2024-2695
CVE-2024-31870
injection
CVE-2024-3813
arbitrary code
CVE-2024-27801
CVE-2024-30120
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3