Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
php board php board 1.0 vulnerabilities and exploits
(subscribe to this query)
409
VMScore
CVE-2002-1821
Ultimate PHP Board (UPB) 1.0 and 1.0b allows remote authenticated users to gain privileges and perform unauthorized actions via direct requests to (1) admin_members.php, (2) admin_config.php, (3) admin_cat.php, or (4) admin_forum.php.
Ultimate Php Board Ultimate Php Board 1.0 Beta
Ultimate Php Board Ultimate Php Board 1.0
585
VMScore
CVE-2003-1401
login.php in php-Board 1.0 stores plaintext passwords in $username.txt with insufficient access control under the web document root, which allows remote malicious users to obtain sensitive information via a direct request.
Php Board Php Board 1.0
1 EDB exploit
445
VMScore
CVE-2002-2276
Ultimate PHP Board (UPB) 1.0 allows remote malicious users to view the physical path of the message board via a direct request to add.php, which leaks the path in an error message.
Ultimate Php Board Ultimate Php Board 1.0
383
VMScore
CVE-2009-2221
Cross-site scripting (XSS) vulnerability in PHP-I-BOARD 1.2 and previous versions allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Php.s3 Php-i-board
Php.s3 Php-i-board 1.1
Php.s3 Php-i-board 1.0
445
VMScore
CVE-2009-2222
Directory traversal vulnerability in PHP-I-BOARD 1.2 and previous versions allows remote malicious users to read arbitrary files via directory traversal sequences in unspecified vectors, probably related to mail.
Php.s3 Php-i-board 1.1
Php.s3 Php-i-board
Php.s3 Php-i-board 1.0
668
VMScore
CVE-2002-1820
register.php in Ultimate PHP Board (UPB) 1.0 and 1.0b uses an administrative account Admin with a capital "A," but allows a remote malicious user to impersonate the administrator by registering an account name of admin with a lower case "a."
Ultimate Php Board Project Ultimate Php Board 1.0
445
VMScore
CVE-2002-1149
The installation procedure for Invision Board suggests that users install the phpinfo.php program under the web root, which leaks sensitive information such as absolute pathnames, OS information, and PHP settings.
Invision Power Services Invision Board 1.0.1
Invision Power Services Invision Board 1.0
454
VMScore
CVE-2006-5203
Invision Power Board (IPB) 2.1.7 and previous versions allows remote restricted administrators to inject arbitrary web script or HTML, or execute arbitrary SQL commands, via a forum description that contains a crafted image with PHP code, which is executed when the user visits th...
Invision Power Services Invision Power Board 1.0.1
Invision Power Services Invision Power Board 1.0.3
Invision Power Services Invision Power Board 2.0
Invision Power Services Invision Power Board 2.0.0
Invision Power Services Invision Power Board 2.0 Pf1
Invision Power Services Invision Power Board 2.0 Pf2
Invision Power Services Invision Power Board 2.1.5
Invision Power Services Invision Power Board 2.1.5 2006-03-08
Invision Power Services Invision Power Board 2.1 Rc1
Invision Power Services Invision Power Board
Invision Power Services Invision Power Board 1.0
Invision Power Services Invision Power Board 1.3.1 Final
Invision Power Services Invision Power Board 1.3 Final
Invision Power Services Invision Power Board 2.0 Alpha3
Invision Power Services Invision Power Board 2.0 Pdr3
Invision Power Services Invision Power Board 2.1.3
Invision Power Services Invision Power Board 2.1.4
Invision Power Services Invision Power Board 2.1 Beta4
Invision Power Services Invision Power Board 2.1 Beta5
Invision Power Services Invision Power Board 1.1.1
Invision Power Services Invision Power Board 1.1.2
Invision Power Services Invision Power Board 2.0.1
668
VMScore
CVE-2007-0189
PHP remote file inclusion vulnerability in index.php in GeoBB Georgian Bulletin Board allows remote malicious users to execute arbitrary PHP code via a URL in the action parameter. NOTE: CVE disputes this issue, since GeoBB 1.0 sets $action to a whitelisted value
Geobb Georgian Bulletin Board
755
VMScore
CVE-2006-6368
PHP remote file inclusion vulnerability in login.php.inc in awrate 1.0 allows remote malicious users to execute arbitrary PHP code via a URL in the toroot parameter to search.php.
Awrate Awrate 1.0
1 EDB exploit
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
camera
bypass
CVE-2024-3592
CVE-2024-37383
CVE-2024-24919
CVE-2024-27822
CVE-2024-36788
CVE-2024-36789
man-in-the-middle
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started