Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
phpbb vulnerabilities and exploits
(subscribe to this query)
10
CVSSv2
CVE-2002-2176
SQL injection vulnerability in Gender MOD 1.1.3 allows remote malicious users to gain administrative access via the user_level parameter in the User Profile page.
Phpbb Group Phpbb 2.0.0
Phpbb Group Phpbb 2.0.1
1 EDB exploit
4.6
CVSSv2
CVE-2001-1472
SQL injection vulnerability in prefs.php in phpBB 1.4.0 and 1.4.1 allows remote authenticated users to execute arbitrary SQL commands and gain administrative access via the viewemail parameter.
Phpbb Group Phpbb 1.4.0
Phpbb Group Phpbb 1.4.1
1 EDB exploit
7.5
CVSSv2
CVE-2007-0680
PHP remote file inclusion vulnerability in includes/functions.php in Phpbb Tweaked 3 and previous versions allows remote malicious users to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
Phpbb Tweaked Phpbb Tweaked 1
Phpbb Tweaked Phpbb Tweaked
1 EDB exploit
5
CVSSv2
CVE-2005-1234
Multiple SQL injection vulnerabilities in phpbb-Auction allow remote malicious users to execute arbitrary SQL commands via the (1) u parameter to auction_rating.php or (2) ar parameter to action_offer.php.
Phpbb Group Phpbb-auction 1.0m
Phpbb Group Phpbb-auction 1.2m
5
CVSSv2
CVE-2005-1235
auction_my_auctions.php in phpbb-Auction 1.2m and previous versions allows remote malicious users to obtain sensitive information via an invalid mode parameter, which leaks the full path in a PHP error message.
Phpbb Group Phpbb-auction 1.0m
Phpbb Group Phpbb-auction 1.2m
6.5
CVSSv2
CVE-2007-2858
SQL injection vulnerability in the IP-Search functionality in the IP-Tracking Mod for phpBB 2.0.x allows remote authenticated administrators to execute arbitrary SQL commands via the Search Query field.
Phpbb Ip-tracking 2.0.1
Phpbb Ip-tracking 2.0.2
Phpbb Ip-tracking 2.0.9
Phpbb Ip-tracking 2.0
Phpbb Ip-tracking 2.0.7
Phpbb Ip-tracking 2.0.8
Phpbb Ip-tracking 2.0.5
Phpbb Ip-tracking 2.0.6
Phpbb Ip-tracking 2.0.3
Phpbb Ip-tracking 2.0.4
NA
CVE-2023-5917
A vulnerability, which was classified as problematic, has been found in phpBB up to 3.3.10. This issue affects the function main of the file phpBB/includes/acp/acp_icons.php of the component Smiley Pack Handler. The manipulation of the argument pak leads to cross site scripting. ...
Phpbb Phpbb
4.3
CVSSv2
CVE-2015-1431
Cross-site scripting (XSS) vulnerability in includes/startup.php in phpBB prior to 3.0.13 allows remote malicious users to inject arbitrary web script or HTML via vectors related to "Relative Path Overwrite."
Phpbb Phpbb
5.1
CVSSv2
CVE-2006-5191
PHP remote file inclusion vulnerability in includes/functions_static_topics.php in the Nivisec Static Topics module for phpBB 1.0 and previous versions allows remote malicious users to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
Phpbb Phpbb
1 EDB exploit
6.8
CVSSv2
CVE-2015-1432
The message_options function in includes/ucp/ucp_pm_options.php in phpBB prior to 3.0.13 does not properly validate the form key, which allows remote malicious users to conduct CSRF attacks and change the full folder setting via unspecified vectors.
Phpbb Phpbb
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
authentication bypass
CVE-2024-30043
camera
CVE-2023-40404
CVE-2024-2793
client side
CVE-2024-4469
CVE-2024-3565
CVE-2024-29825
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
2
3
4
5
6
7
8
9
10
NEXT »