Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
phpbb vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2001-1472
SQL injection vulnerability in prefs.php in phpBB 1.4.0 and 1.4.1 allows remote authenticated users to execute arbitrary SQL commands and gain administrative access via the viewemail parameter.
Phpbb Group Phpbb 1.4.0
Phpbb Group Phpbb 1.4.1
1 EDB exploit
NA
CVE-2002-2176
SQL injection vulnerability in Gender MOD 1.1.3 allows remote malicious users to gain administrative access via the user_level parameter in the User Profile page.
Phpbb Group Phpbb 2.0.0
Phpbb Group Phpbb 2.0.1
1 EDB exploit
NA
CVE-2007-0680
PHP remote file inclusion vulnerability in includes/functions.php in Phpbb Tweaked 3 and previous versions allows remote malicious users to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
Phpbb Tweaked Phpbb Tweaked 1
Phpbb Tweaked Phpbb Tweaked
1 EDB exploit
NA
CVE-2005-1234
Multiple SQL injection vulnerabilities in phpbb-Auction allow remote malicious users to execute arbitrary SQL commands via the (1) u parameter to auction_rating.php or (2) ar parameter to action_offer.php.
Phpbb Group Phpbb-auction 1.0m
Phpbb Group Phpbb-auction 1.2m
NA
CVE-2005-1235
auction_my_auctions.php in phpbb-Auction 1.2m and previous versions allows remote malicious users to obtain sensitive information via an invalid mode parameter, which leaks the full path in a PHP error message.
Phpbb Group Phpbb-auction 1.0m
Phpbb Group Phpbb-auction 1.2m
NA
CVE-2007-2858
SQL injection vulnerability in the IP-Search functionality in the IP-Tracking Mod for phpBB 2.0.x allows remote authenticated administrators to execute arbitrary SQL commands via the Search Query field.
Phpbb Ip-tracking 2.0.1
Phpbb Ip-tracking 2.0.2
Phpbb Ip-tracking 2.0.9
Phpbb Ip-tracking 2.0
Phpbb Ip-tracking 2.0.7
Phpbb Ip-tracking 2.0.8
Phpbb Ip-tracking 2.0.5
Phpbb Ip-tracking 2.0.6
Phpbb Ip-tracking 2.0.3
Phpbb Ip-tracking 2.0.4
NA
CVE-2006-7168
PHP remote file inclusion vulnerability in includes/not_mem.php in the Add Name module for PHP allows remote malicious users to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
Phpbb Phpbb -
1 EDB exploit
NA
CVE-2006-5191
PHP remote file inclusion vulnerability in includes/functions_static_topics.php in the Nivisec Static Topics module for phpBB 1.0 and previous versions allows remote malicious users to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
Phpbb Phpbb
1 EDB exploit
NA
CVE-2015-1431
Cross-site scripting (XSS) vulnerability in includes/startup.php in phpBB prior to 3.0.13 allows remote malicious users to inject arbitrary web script or HTML via vectors related to "Relative Path Overwrite."
Phpbb Phpbb
8.8
CVSSv3
CVE-2001-1471
prefs.php in phpBB 1.4.0 and previous versions allows remote authenticated users to execute arbitrary PHP code via an invalid language value, which prevents the variables (1) $l_statsblock in prefs.php or (2) $l_privnotify in auth.php from being properly initialized, which can be...
Phpbb Phpbb
1 EDB exploit
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2020-4463
CVE-2024-3400
deserialization
CVE-2024-21788
CVE-2023-42433
CVE-2024-21841
CVE-2024-22095
local file inclusion
memory leak
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
2
3
4
5
6
7
8
9
10
NEXT »