Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
php forum vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv2
CVE-2007-1604
Multiple unrestricted file upload vulnerabilities in w-Agora (Web-Agora) allow remote malicious users to upload and execute arbitrary PHP code (1) via a forum message with an attached file, which is stored under forums/hello/hello/notes/ or (2) by using browse_avatar.php to uploa...
W-agora W-agora 4.2.1
1 EDB exploit
6.5
CVSSv2
CVE-2009-2371
Advanced Forum 6.x prior to 6.x-1.1, a module for Drupal, does not prevent users from modifying user signatures after the associated comment format has been changed to an administrator-controlled input format, which allows remote authenticated users to inject arbitrary web script...
Michelle Cox Advanced Forum 6.x-1.x-dev
Michelle Cox Advanced Forum 6.x-1.0
2.6
CVSSv2
CVE-2006-1898
Multiple cross-site scripting (XSS) vulnerabilities in Ralph Capper Tiny PHP Forum (TPF) 3.6 allow remote malicious users to inject arbitrary web script or HTML via (1) the uname parameter in a view action in profile.php and (2) a login name. NOTE: the "Access to hash passwo...
Ralph Capper Tinyphpforum 3.6
4.3
CVSSv2
CVE-2007-5575
Cross-site request forgery (CSRF) vulnerability in 1024 CMS 1.2.5 allows remote malicious users to perform some actions as administrators, as demonstrated by (1) an unspecified action that creates a file containing PHP code and (2) unspecified use of the forum component. NOTE: th...
Treble Designs 1024 Cms 1.2.5
6.8
CVSSv2
CVE-2008-3555
Directory traversal vulnerability in index.php in (1) WSN Forum 4.1.43 and previous versions, (2) Gallery 4.1.30 and previous versions, (3) Knowledge Base (WSNKB) 4.1.36 and previous versions, (4) Links 4.1.44 and previous versions, and possibly (5) Classifieds prior to 4.1.30 al...
Wsn Links 4.0.14
Wsn Links 4.0.15
Wsn Links 4.0.21
Wsn Links 4.0.22
Wsn Links 4.0.3
Wsn Links 4.0.30
Wsn Links 4.0.37
Wsn Links 4.0.38
Wsn Links 4.0.7
Wsn Links 4.0.8
Wsn Links 4.1.14
Wsn Links 4.1.15
Wsn Links 4.1.21
Wsn Links 4.1.22
Wsn Links 4.1.29
Wsn Links 4.1.3
Wsn Links 4.1.37
Wsn Links 4.1.38
Wsn Links 4.1.44
Wsn Links 4.1.5
Wsn Knowledge Base
Wsn Links 4.0.10
1 EDB exploit
6.5
CVSSv2
CVE-2019-12831
In MyBB prior to 1.8.21, an attacker can abuse a default behavior of MySQL on many systems (that leads to truncation of strings that are too long for a database column) to create a PHP shell in the cache directory of a targeted forum via a crafted XML import, as demonstrated by t...
Mybb Mybb
6.5
CVSSv2
CVE-2020-13443
ExpressionEngine prior to 5.3.2 allows remote malicious users to upload and execute arbitrary code in a .php%20 file via Compose Msg, Add attachment, and Save As Draft actions. A user with low privileges (member) is able to upload this. It is possible to bypass the MIME type chec...
Expressionengine Expressionengine
6.8
CVSSv2
CVE-2005-3347
Multiple directory traversal vulnerabilities in index.php in phpSysInfo 2.4 and previous versions, as used in phpgroupware 0.9.16 and previous versions, and egrouwpware prior to 1.0.0.009, allow remote malicious users to include arbitrary files via .. (dot dot) sequences in the (...
Phpgroupware Phpgroupware 0.9.16
4.3
CVSSv2
CVE-2005-3348
HTTP response splitting vulnerability in index.php in phpSysInfo 2.4 and previous versions, as used in phpgroupware 0.9.16 and previous versions, and egroupware prior to 1.0.0.009, allows remote malicious users to spoof web content and poison web caches via CRLF sequences in the ...
Phpsysinfo Phpsysinfo 2.3
Phpsysinfo Phpsysinfo 2.4
Phpsysinfo Phpsysinfo 2.0
Phpsysinfo Phpsysinfo 2.1
4.6
CVSSv2
CVE-2006-4758
phpBB 2.0.21 does not properly handle pathnames ending in %00, which allows remote authenticated administrative users to upload arbitrary files, as demonstrated by a query to admin/admin_board.php with an avatar_path parameter ending in .php%00.
Phpbb Group Phpbb 2.0.21
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
encryption
CVE-2024-4331
CVE-2024-26925
arbitrary code
CVE-2006-4304
CVE-2024-25458
CVE-2024-27077
reflected XSS
CVE-2024-4059
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
4
5
6
7
8
9
10
NEXT »