Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
php forum vulnerabilities and exploits
(subscribe to this query)
6.8
CVSSv2
CVE-2008-2220
Multiple PHP remote file inclusion vulnerabilities in Interact Learning Community Environment Interact 2.4.1, when register_globals is enabled, allow remote malicious users to execute arbitrary PHP code via a URL in the (1) CONFIG[LANGUAGE_CPATH] parameter to modules/forum/embedf...
Interact Interact 2.4.1
1 EDB exploit
7.5
CVSSv2
CVE-2006-6041
Multiple PHP remote file inclusion vulnerabilities in Laurent Van den Reysen WORK system e-commerce 3.0.2, and other versions prior to 3.0.4, allow remote malicious users to execute arbitrary PHP code via a URL in the g_include parameter to (1) index.php, (2) module/forum/forum.p...
Laurent Van Den Reysen Work System E-commerce
1 EDB exploit
7.5
CVSSv2
CVE-2010-2132
Multiple PHP remote file inclusion vulnerabilities in Open Education System (OES) 0.1 beta allow remote malicious users to execute arbitrary PHP code via a URL in the CONF_INCLUDE_PATH parameter to (1) forum/admin.php and (2) plotgraph/index.php in admin/modules/modules/, and (3)...
Danny Ho Oes 0.1
7.5
CVSSv2
CVE-2005-2781
The Avatar upload feature in FUD Forum prior to 2.7.0 does not properly verify uploaded files, which allows remote malicious users to execute arbitrary PHP code via a file with a .php extension that contains image data followed by PHP code.
Ilia Alshanetsky Fudforum 2.2.0
Ilia Alshanetsky Fudforum 2.2.1
Ilia Alshanetsky Fudforum 2.2.2
Ilia Alshanetsky Fudforum 2.3.3
Ilia Alshanetsky Fudforum 2.3.4
Ilia Alshanetsky Fudforum 2.5.2
Ilia Alshanetsky Fudforum 2.6.0
Ilia Alshanetsky Fudforum 2.6.2
Ilia Alshanetsky Fudforum 2.6.3
Ilia Alshanetsky Fudforum 2.7.0
Ilia Alshanetsky Fudforum 2.2.3
Ilia Alshanetsky Fudforum 2.2.4
Ilia Alshanetsky Fudforum 2.3.5
Ilia Alshanetsky Fudforum 2.3.6
Ilia Alshanetsky Fudforum 2.6.1
Ilia Alshanetsky Fudforum 2.6.10
Ilia Alshanetsky Fudforum 2.6.4
Ilia Alshanetsky Fudforum 2.6.5
Ilia Alshanetsky Fudforum 2.1.0
Ilia Alshanetsky Fudforum 2.1.1
Ilia Alshanetsky Fudforum 2.2.5
Ilia Alshanetsky Fudforum 2.3.0
7.5
CVSSv2
CVE-2007-2317
Multiple PHP remote file inclusion vulnerabilities in MiniBB Forum 1.5a and previous versions, as used by TOSMO/Mambo 4.0.12 and probably other products, allow remote malicious users to execute arbitrary PHP code via a URL in the absolute_path parameter to bb_plugins.php in (1) c...
Minibb Minibb
Tosmo Mambo Tosmo Mambo
1 EDB exploit
2.6
CVSSv2
CVE-2006-5511
Direct static code injection vulnerability in delete.php in JaxUltraBB (JUBB) 2.0, when register_globals is enabled, allows remote malicious users to inject arbitrary web script, HTML, or PHP via the contents parameter, whose value is prepended to the file specified by the forum ...
Jaxultrabb Jaxultrabb 2.0
1 EDB exploit
7.5
CVSSv2
CVE-2005-2498
Eval injection vulnerability in PHPXMLRPC 1.1.1 and previous versions (PEAR XML-RPC for PHP), as used in multiple products including (1) Drupal, (2) phpAdsNew, (3) phpPgAds, and (4) phpgroupware, allows remote malicious users to execute arbitrary PHP code via certain nested XML t...
Gggeek Phpxmlrpc
Debian Debian Linux 3.1
7.5
CVSSv2
CVE-2006-3173
Multiple PHP remote file inclusion vulnerabilities in Content*Builder 0.7.5 allow remote malicious users to execute arbitrary PHP code via a URL in the (1) path[cb] parameter to (a) libraries/comment/postComment.php and (b) modules/poll/poll.php, (2) rel parameter to (c) modules/...
Content\\*builder Content\\*builder 0.7.5
1 EDB exploit
5.1
CVSSv2
CVE-2006-5203
Invision Power Board (IPB) 2.1.7 and previous versions allows remote restricted administrators to inject arbitrary web script or HTML, or execute arbitrary SQL commands, via a forum description that contains a crafted image with PHP code, which is executed when the user visits th...
Invision Power Services Invision Power Board 1.0.1
Invision Power Services Invision Power Board 1.0.3
Invision Power Services Invision Power Board 2.0
Invision Power Services Invision Power Board 2.0.0
Invision Power Services Invision Power Board 2.0 Pf1
Invision Power Services Invision Power Board 2.0 Pf2
Invision Power Services Invision Power Board 2.1.5
Invision Power Services Invision Power Board 2.1.5 2006-03-08
Invision Power Services Invision Power Board 2.1 Rc1
Invision Power Services Invision Power Board
Invision Power Services Invision Power Board 1.0
Invision Power Services Invision Power Board 1.3.1 Final
Invision Power Services Invision Power Board 1.3 Final
Invision Power Services Invision Power Board 2.0 Alpha3
Invision Power Services Invision Power Board 2.0 Pdr3
Invision Power Services Invision Power Board 2.1.3
Invision Power Services Invision Power Board 2.1.4
Invision Power Services Invision Power Board 2.1 Beta4
Invision Power Services Invision Power Board 2.1 Beta5
Invision Power Services Invision Power Board 1.1.1
Invision Power Services Invision Power Board 1.1.2
Invision Power Services Invision Power Board 2.0.1
10
CVSSv2
CVE-2020-13873
A SQL Injection vulnerability in get_topic_info() in sys/CODOF/Forum/Topic.php in Codoforum prior to 4.9 allows remote attackers (pre-authentication) to bypass the admin page via a leaked password-reset token of the admin. (As an admin, an attacker can upload a PHP shell and exec...
Codologic Codoforum
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-27322
CVE-2006-4304
wireless
CVE-2023-23022
local file inclusion
CVE-2024-27058
CVE-2024-33820
open redirect
CVE-2024-27079
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
3
4
5
6
7
8
9
10
NEXT »