Skip to main content

Vendor/product archive

phpbb_group / phpbb CVEs

Beta · best-effort

82 CVEs tagged to phpbb_group / phpbb7 Critical, 24 High, 49 Medium, 2 Low, 0 Unrated.

CVE-2007-1695

Published Mar 27, 2007

PHP remote file inclusion vulnerability in includes/usercp_register.php in phpBB 2.0.19 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path para…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-2219

Published Feb 8, 2007

phpBB 2.0.20 does not verify user-specified input variable types before being passed to type-dependent functions, which allows remote attackers to obtain sensitive information, as…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6839

Published Dec 31, 2006

Unspecified vulnerability in phpBB before 2.0.22 has unknown impact and remote attack vectors related to "criteria for 'bad' redirection targets."

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-6840

Published Dec 31, 2006

Unspecified vulnerability in phpBB before 2.0.22 has unknown impact and remote attack vectors related to a "negative start parameter."

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-6841

Published Dec 31, 2006

Certain forms in phpBB before 2.0.22 lack session checks, which has unknown impact and remote attack vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-6508

Published Dec 14, 2006

Cross-site request forgery (CSRF) vulnerability in phpBB 2.0.21 allows remote authenticated users to send unauthorized messages as an arbitrary user via unspecified vectors. NOTE…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6421

Published Dec 10, 2006

Cross-site scripting (XSS) vulnerability in the private message box implementation (privmsg.php) in phpBB 2.0.x allows remote authenticated users to inject arbitrary web script or…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-5435

Published Oct 20, 2006

PHP remote file inclusion vulnerability in groupcp.php in phpBB 2.0.10 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-5209

Published Oct 10, 2006

PHP remote file inclusion vulnerability in admin/admin_topic_action_logging.php in Admin Topic Action Logging Mod 0.95 and earlier, as used in phpBB 2.0 up to 2.0.21, allows remot…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4758

Published Sep 13, 2006

phpBB 2.0.21 does not properly handle pathnames ending in %00, which allows remote authenticated administrative users to upload arbitrary files, as demonstrated by a query to admi…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4450

Published Aug 30, 2006

usercp_avatar.php in PHPBB 2.0.20, when avatar uploading is enabled, allows remote attackers to use the server as a web proxy by submitting a URL to the avatarurl parameter, which…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-2865

Published Jun 6, 2006

PHP remote file inclusion vulnerability in template.php in phpBB 2 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. NOTE: followup posts hav…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-2359

Published May 15, 2006

Cross-site scripting (XSS) vulnerability in charts.php in the Chart mod for phpBB allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: this…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-2360

Published May 15, 2006

SQL injection vulnerability in charts.php in the Chart mod for phpBB allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-2134

Published May 2, 2006

PHP remote file inclusion vulnerability in /includes/kb_constants.php in Knowledge Base Mod for PHPbb 2.0.2 and earlier allows remote attackers to execute arbitrary PHP code via a…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1895

Published Apr 20, 2006

Direct static code injection vulnerability in includes/template.php in phpBB allows remote authenticated users with write access to execute arbitrary PHP code by modifying a templ…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1896

Published Apr 20, 2006

Unspecified vulnerability in phpBB allows remote authenticated users with Administration Panel access to execute arbitrary PHP code via crafted Font Colour 3 ($theme[fontcolor3] v…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1775

Published Apr 13, 2006

Multiple cross-site scripting (XSS) vulnerabilities in phpBB 2.0.19 allow remote attackers to inject arbitrary web script or HTML via the (1) Site Description field in (a) admin_b…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1603

Published Apr 4, 2006

Cross-site scripting (XSS) vulnerability in profile.php in phpBB 2.0.19 allows remote attackers to inject arbitrary web script or HTML via the cur_password parameter. NOTE: the p…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0632

Published Feb 10, 2006

The gen_rand_string function in phpBB 2.0.19 uses insufficiently random data (small value space) to create the activation key ("validation ID") that is sent by e-mail when establi…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0437

Published Feb 6, 2006

Cross-site scripting (XSS) vulnerability in admin_smilies.php in phpBB 2.0.19 allows remote attackers to inject arbitrary web script or HTML via Javascript events such as "onmouse…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0438

Published Feb 6, 2006

Cross-site request forgery (CSRF) vulnerability in phpBB 2.0.19, when Link to off-site Avatar or bbcode (IMG) are enabled, allows remote attackers to perform unauthorized actions…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0450

Published Jan 27, 2006

phpBB 2.0.19 and earlier allows remote attackers to cause a denial of service (application crash) by (1) registering many users through profile.php or (2) using search.php to sear…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0063

Published Jan 5, 2006

Cross-site scripting (XSS) vulnerability in phpBB 2.0.19, when "Allowed HTML tags" is enabled, allows remote attackers to inject arbitrary web script or HTML via a permitted HTML…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-3536

Published Dec 22, 2005

SQL injection vulnerability in phpBB 2 before 2.0.18 allows remote attackers to execute arbitrary SQL commands via the topic type.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 82 CVEsPage 1 of 4