Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
punbb punbb 1.2.12 vulnerabilities and exploits
(subscribe to this query)
320
VMScore
CVE-2006-4759
PunBB 1.2.12 does not properly handle an avatar directory pathname ending in %00, which allows remote authenticated administrative users to upload arbitrary files and execute code, as demonstrated by a query to admin_options.php with an avatars_dir parameter ending in %00. NOTE: ...
Punbb Punbb 1.2.12
605
VMScore
CVE-2008-7241
Cross-site request forgery (CSRF) vulnerability in PunBB prior to 1.2.17 allows remote malicious users to hijack the authentication of unspecified users for requests related to a logout, probably a forced logout.
Punbb Punbb 1.2
Punbb Punbb 1.2.15
Punbb Punbb 1.2.13
Punbb Punbb 1.2.12
Punbb Punbb 1.1.3
Punbb Punbb 1.1.2
Punbb Punbb 1.1.1
Punbb Punbb 1.1
Punbb Punbb 1.2.5
Punbb Punbb 1.2.4
Punbb Punbb 1.2.3
Punbb Punbb 1.2.2
Punbb Punbb 1.1.5
Punbb Punbb 1.2.14
Punbb Punbb 1.2.10
Punbb Punbb 1.2.7
Punbb Punbb 1.2.9
Punbb Punbb 1.1.4
Punbb Punbb 1.2.1
Punbb Punbb 1.2.11
Punbb Punbb 1.0
Punbb Punbb 1.2.6
890
VMScore
CVE-2008-3335
Unspecified vulnerability in PunBB prior to 1.2.19 allows remote malicious users to inject arbitrary SMTP commands via unknown vectors.
Punbb Punbb 1.0
Punbb Punbb 1.1
Punbb Punbb 1.2.1
Punbb Punbb 1.2.10
Punbb Punbb 1.2.17
Punbb Punbb 1.2.2
Punbb Punbb
Punbb Punbb 1.1.3
Punbb Punbb 1.1.4
Punbb Punbb 1.2.13
Punbb Punbb 1.2.14
Punbb Punbb 1.2.5
Punbb Punbb 1.2.6
Punbb Punbb 1.0.1
Punbb Punbb 1.1.1
Punbb Punbb 1.1.2
Punbb Punbb 1.2.11
Punbb Punbb 1.2.12
Punbb Punbb 1.2.3
Punbb Punbb 1.2.4
Punbb Punbb 1.1.5
Punbb Punbb 1.2
383
VMScore
CVE-2008-3336
Multiple cross-site scripting (XSS) vulnerabilities in PunBB prior to 1.2.19 allow remote malicious users to inject arbitrary web script or HTML via unspecified vectors in (1) include/parser.php and (2) moderate.php.
Punbb Punbb 1.0
Punbb Punbb 1.1.4
Punbb Punbb 1.1.5
Punbb Punbb 1.2.15
Punbb Punbb 1.2.16
Punbb Punbb 1.2.7
Punbb Punbb 1.2.8
Punbb Punbb 1.0.1
Punbb Punbb 1.1
Punbb Punbb 1.1.1
Punbb Punbb 1.2.10
Punbb Punbb 1.2.11
Punbb Punbb 1.2.12
Punbb Punbb 1.2.3
Punbb Punbb 1.2.4
Punbb Punbb
Punbb Punbb 1.2
Punbb Punbb 1.2.1
Punbb Punbb 1.2.17
Punbb Punbb 1.2.2
Punbb Punbb 1.2.9
Punbb Punbb 1.1.2
454
VMScore
CVE-2006-5736
SQL injection vulnerability in search.php in PunBB prior to 1.2.14, when the PHP installation is vulnerable to CVE-2006-3017, allows remote malicious users to execute arbitrary SQL commands via the result_list array parameter, which is not initialized.
Punbb Punbb 1.0 Beta2
Punbb Punbb 1.0 Beta3
Punbb Punbb 1.1.4
Punbb Punbb 1.1.5
Punbb Punbb 1.2.3
Punbb Punbb 1.0
Punbb Punbb 1.0.1
Punbb Punbb 1.1
Punbb Punbb 1.1.1
Punbb Punbb 1.2.10
Punbb Punbb 1.2.11
Punbb Punbb 1.2.7
Punbb Punbb 1.2.8
Punbb Punbb 1.2.9
Punbb Punbb 1.0 Alpha
Punbb Punbb 1.0 Beta1
Punbb Punbb 1.0 Beta1a
Punbb Punbb 1.1.2
Punbb Punbb 1.1.3
Punbb Punbb 1.2.12
Punbb Punbb 1.2.2
Punbb Punbb
187
VMScore
CVE-2006-5738
Multiple SQL injection vulnerabilities in PunBB prior to 1.2.14 allow remote authenticated administrators to execute arbitrary SQL commands via unspecified vectors.
Punbb Punbb 1.0 Beta2
Punbb Punbb 1.0 Beta3
Punbb Punbb 1.0 Rc1
Punbb Punbb 1.0 Rc2
Punbb Punbb 1.2.4
Punbb Punbb 1.2.5
Punbb Punbb 1.2.6
Punbb Punbb 1.2.7
Punbb Punbb 1.0.1
Punbb Punbb 1.0 Beta1
Punbb Punbb 1.1.1
Punbb Punbb 1.1.3
Punbb Punbb 1.2.12
Punbb Punbb 1.2.3
Punbb Punbb 1.2.8
Punbb Punbb
Punbb Punbb 1.0
Punbb Punbb 1.1.4
Punbb Punbb 1.1.5
Punbb Punbb 1.2
Punbb Punbb 1.2.1
Punbb Punbb 1.2.10
383
VMScore
CVE-2008-5435
Cross-site scripting (XSS) vulnerability in moderate.php in PunBB prior to 1.3.1 allows remote malicious users to inject arbitrary web script or HTML via a topic subject.
Punbb Punbb 1.3
Punbb Punbb 1.2.16
Punbb Punbb 1.2.15
Punbb Punbb 1.2.14
Punbb Punbb 1.2.7
Punbb Punbb 1.2.6
Punbb Punbb 1.1.1
Punbb Punbb 1.1.5
Punbb Punbb 1.0
Punbb Punbb 1.2.21
Punbb Punbb 1.2.13
Punbb Punbb 1.2.12
Punbb Punbb 1.2.5
Punbb Punbb 1.2.4
Punbb Punbb 1.2
Punbb Punbb 1.1.4
Punbb Punbb 1.2.20
Punbb Punbb 1.2.19
Punbb Punbb 1.2.11
Punbb Punbb 1.2.10
Punbb Punbb 1.2.3
Punbb Punbb 1.2.2
355
VMScore
CVE-2008-1484
The password reset feature in PunBB 1.2.16 and previous versions uses predictable random numbers based on the system time, which allows remote authenticated users to determine the new password via a brute force attack on a seed that is based on the approximate creation time of th...
Punbb Punbb 1.0 Alpha
Punbb Punbb 1.0 Beta1
Punbb Punbb 1.1.3
Punbb Punbb 1.1.4
Punbb Punbb 1.0 Beta2
Punbb Punbb 1.0 Beta3
Punbb Punbb 1.0 Rc1
Punbb Punbb 1.1.5
Punbb Punbb 1.0
Punbb Punbb 1.0.1
Punbb Punbb 1.1.1
Punbb Punbb 1.1.2
Punbb Punbb 1.2.11
Punbb Punbb 1.2.12
Punbb Punbb 1.2.4
Punbb Punbb 1.2.5
Punbb Punbb 1.2
Punbb Punbb 1.2.15
Punbb Punbb 1.2.16
Punbb Punbb 1.2.8
Punbb Punbb 1.2.9
Punbb Punbb 1.2.13
1 EDB exploit
383
VMScore
CVE-2008-1485
Cross-site scripting (XSS) vulnerability in PunBB 1.2.16 and previous versions allows remote malicious users to inject arbitrary web script or HTML via the get_host parameter to moderate.php.
Punbb Punbb 1.0 Alpha
Punbb Punbb 1.0 Beta1
Punbb Punbb 1.1.2
Punbb Punbb 1.1.3
Punbb Punbb 1.2.12
Punbb Punbb 1.2.13
Punbb Punbb 1.2.6
Punbb Punbb 1.2.7
Punbb Punbb 1.0 Rc1
Punbb Punbb 1.0 Rc2
Punbb Punbb 1.2
Punbb Punbb 1.2.1
Punbb Punbb 1.2.2
Punbb Punbb 1.2.3
Punbb Punbb 1.0 Beta2
Punbb Punbb 1.0 Beta3
Punbb Punbb 1.1.4
Punbb Punbb 1.1.5
Punbb Punbb 1.2.14
Punbb Punbb 1.2.15
Punbb Punbb 1.2.16
Punbb Punbb 1.2.8
383
VMScore
CVE-2009-4894
Multiple cross-site scripting (XSS) vulnerabilities in profile.php in PunBB prior to 1.3.4 allow remote malicious users to inject arbitrary web script or HTML via the (1) password or (2) e-mail.
Punbb Punbb
Punbb Punbb 1.3.1
Punbb Punbb 1.2.19
Punbb Punbb 1.2.2
Punbb Punbb 1.2.20
Punbb Punbb 1.2.21
Punbb Punbb 1.1.5
Punbb Punbb 1.0
Punbb Punbb 1.0.1
Punbb Punbb 1.2.10
Punbb Punbb 1.2.11
Punbb Punbb 1.2.12
Punbb Punbb 1.2.13
Punbb Punbb 1.2.7
Punbb Punbb 1.2.8
Punbb Punbb 1.2.9
Punbb Punbb 1.1
Punbb Punbb 1.3
Punbb Punbb 1.2.1
Punbb Punbb 1.2.14
Punbb Punbb 1.2.16
Punbb Punbb 1.2.18
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-52710
arbitrary
CVE-2024-5272
CVE-2024-2961
brute force
remote
CVE-2024-32944
CVE-2024-36241
CVE-2024-5274
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »