Skip to main content

Vendor archive

phpbb_group CVEs

Beta · best-effort

93 CVEs tagged to vendor phpbb_group7 Critical, 28 High, 56 Medium, 2 Low, 0 Unrated.

CVE-2007-1695

Published Mar 27, 2007

PHP remote file inclusion vulnerability in includes/usercp_register.php in phpBB 2.0.19 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path para…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-7076

Published Mar 2, 2007

Cross-site scripting (XSS) vulnerability in guestbook.php in Advanced Guestbook 2.4 for phpBB allows remote attackers to inject arbitrary web script or HTML via the entry paramete…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-7077

Published Mar 2, 2007

SQL injection vulnerability in guestbook.php in Advanced Guestbook 2.4 for phpBB allows remote attackers to execute arbitrary SQl commands via the entry parameter.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-2219

Published Feb 8, 2007

phpBB 2.0.20 does not verify user-specified input variable types before being passed to type-dependent functions, which allows remote attackers to obtain sensitive information, as…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6839

Published Dec 31, 2006

Unspecified vulnerability in phpBB before 2.0.22 has unknown impact and remote attack vectors related to "criteria for 'bad' redirection targets."

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-6840

Published Dec 31, 2006

Unspecified vulnerability in phpBB before 2.0.22 has unknown impact and remote attack vectors related to a "negative start parameter."

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-6841

Published Dec 31, 2006

Certain forms in phpBB before 2.0.22 lack session checks, which has unknown impact and remote attack vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-6508

Published Dec 14, 2006

Cross-site request forgery (CSRF) vulnerability in phpBB 2.0.21 allows remote authenticated users to send unauthorized messages as an arbitrary user via unspecified vectors. NOTE…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6421

Published Dec 10, 2006

Cross-site scripting (XSS) vulnerability in the private message box implementation (privmsg.php) in phpBB 2.0.x allows remote authenticated users to inject arbitrary web script or…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-5435

Published Oct 20, 2006

PHP remote file inclusion vulnerability in groupcp.php in phpBB 2.0.10 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-5209

Published Oct 10, 2006

PHP remote file inclusion vulnerability in admin/admin_topic_action_logging.php in Admin Topic Action Logging Mod 0.95 and earlier, as used in phpBB 2.0 up to 2.0.21, allows remot…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4779

Published Sep 14, 2006

PHP remote file inclusion vulnerability in includes/functions_portal.php in Vitrax Premodded phpBB 1.0.6-R3 and earlier allows remote attackers to execute arbitrary PHP code via a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4758

Published Sep 13, 2006

phpBB 2.0.21 does not properly handle pathnames ending in %00, which allows remote authenticated administrative users to upload arbitrary files, as demonstrated by a query to admi…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4450

Published Aug 30, 2006

usercp_avatar.php in PHPBB 2.0.20, when avatar uploading is enabled, allows remote attackers to use the server as a web proxy by submitting a URL to the avatarurl parameter, which…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3940

Published Jul 31, 2006

Multiple SQL injection vulnerabilities in phpbb-Auction allow remote attackers to execute arbitrary SQL commands via (1) the ar parameter in auction_room.php and (2) the u paramet…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-2865

Published Jun 6, 2006

PHP remote file inclusion vulnerability in template.php in phpBB 2 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. NOTE: followup posts hav…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-2359

Published May 15, 2006

Cross-site scripting (XSS) vulnerability in charts.php in the Chart mod for phpBB allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: this…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-2360

Published May 15, 2006

SQL injection vulnerability in charts.php in the Chart mod for phpBB allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-2245

Published May 9, 2006

PHP remote file inclusion vulnerability in auction\auction_common.php in Auction mod 1.3m for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_ro…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-2150

Published May 3, 2006

PHP remote file inclusion vulnerability in top/list.php in phpBB TopList 1.3.8 and earlier allows remote attackers to include arbitrary files via the returnpath parameter.

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-2151

Published May 3, 2006

PHP remote file inclusion vulnerability in toplist.php in phpBB TopList 1.3.8 and earlier, when register_globals is enabled, allows remote attackers to include arbitrary files via…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-2152

Published May 3, 2006

PHP remote file inclusion vulnerability in admin/addentry.php in phpBB Advanced Guestbook 2.4.0 and earlier, when register_globals is enabled, allows remote attackers to include a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-2134

Published May 2, 2006

PHP remote file inclusion vulnerability in /includes/kb_constants.php in Knowledge Base Mod for PHPbb 2.0.2 and earlier allows remote attackers to execute arbitrary PHP code via a…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1895

Published Apr 20, 2006

Direct static code injection vulnerability in includes/template.php in phpBB allows remote authenticated users with write access to execute arbitrary PHP code by modifying a templ…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1896

Published Apr 20, 2006

Unspecified vulnerability in phpBB allows remote authenticated users with Administration Panel access to execute arbitrary PHP code via crafted Font Colour 3 ($theme[fontcolor3] v…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 93 CVEsPage 1 of 4