Skip to main content

Vendor/product archive

phpbb_group / phpbb CVEs

Beta · best-effort

82 CVEs tagged to phpbb_group / phpbb7 Critical, 24 High, 49 Medium, 2 Low, 0 Unrated.

CVE-2005-0258

Published Mar 14, 2005

Directory traversal vulnerability in (1) usercp_register.php and (2) usercp_avatar.php for phpBB 2.0.11, and possibly other versions, with gallery avatars enabled, allows remote a…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0259

Published Mar 14, 2005

phpBB 2.0.11, and possibly other versions, with remote avatars and avatar uploading enabled, allows local users to read arbitrary files by providing both a local and remote locati…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0603

Published Feb 28, 2005

viewtopic.php in phpBB 2.0.12 and earlier allows remote attackers to obtain sensitive information via a highlight parameter containing invalid regular expression syntax, which rev…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1535

Published Dec 31, 2004

PHP remote file inclusion vulnerability in admin_cash.php for the Cash Mod module for phpBB allows remote attackers to execute arbitrary PHP code by modifying the phpbb_root_path…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-1809

Published Dec 31, 2004

Cross-site scripting (XSS) vulnerability in phpBB 2.0.6d and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) postdays parameter to viewtopic.php…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2054

Published Dec 31, 2004

CRLF injection vulnerability in PhpBB 2.0.4 and 2.0.9 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via (1) th…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2350

Published Dec 31, 2004

SQL injection vulnerability in search.php for phpBB 1.0 through 2.0.6 allows remote attackers to execute arbitrary SQL and gain privileges via the search_results parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-2358

Published Dec 31, 2004

Cross-site scripting (XSS) vulnerability in admin_words.php for phpBB 2.0.6c allows remote attackers to inject arbitrary web script or HTML via the id parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2130

Published Dec 23, 2004

Multiple cross-site scripting (XSS) vulnerabilities in privmsg.php in phpBB 2.0.6 allow remote attackers to execute arbitrary script or HTML via the (1) folder or (2) mode variabl…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0339

Published Nov 23, 2004

Cross-site scripting (XSS) vulnerability in ViewTopic.php in phpBB, possibly 2.0.6c and earlier, allows remote attackers to execute arbitrary script or HTML as other users via the…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1315

Published Nov 12, 2004

viewtopic.php in phpBB 2.x before 2.0.11 improperly URL decodes the highlight parameter when extracting words and phrases to highlight, which allows remote attackers to execute ar…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-0729

Published Jul 27, 2004

PhpBB 2.0.8 allows remote attackers to gain sensitive information via an invalid (1) category_rows parameter to index.php, (2) faq parameter to faq.php, or (3) ranksrow parameter…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0730

Published Jul 27, 2004

Multiple cross-site scripting (XSS) vulnerabilities in PhpBB 2.0.8 allow remote attackers to inject arbitrary web script or HTML via (1) the cat_title parameter in index.php, (2)…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2055

Published Jul 19, 2004

Cross-site scripting (XSS) vulnerability in search.php for PhpBB 2.0.4 and 2.0.9 allows remote attackers to inject arbitrary HTMl or web script via the search_author parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1943

Published Apr 19, 2004

PHP remote file inclusion vulnerability in album_portal.php in phpBB modified by Przemo 1.8 allows remote attackers to execute arbitrary PHP code via the phpbb_root_path parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-1950

Published Apr 19, 2004

phpBB 2.0.8a and earlier trusts the IP address that is in the X-Forwarded-For in the HTTP header, which allows remote attackers to spoof IP addresses.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1244

Published Dec 31, 2003

SQL injection vulnerability in page_header.php in phpBB 2.0, 2.0.1 and 2.0.2 allows remote attackers to brute force user passwords and possibly gain unauthorized access to forums…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-1373

Published Dec 31, 2003

Directory traversal vulnerability in auth.php for PhpBB 1.4.0 through 1.4.4 allows remote attackers to read and include arbitrary files via .. (dot dot) sequences followed by NULL…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1215

Published Dec 29, 2003

SQL injection vulnerability in groupcp.php for phpBB 2.0.6 and earlier allows group moderators to perform unauthorized activities via the sql_in parameter.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1216

Published Nov 27, 2003

SQL injection vulnerability in search.php for phpBB 2.0.6 and earlier allows remote attackers to execute arbitrary SQL and gain privileges via the search_id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0484

Published Aug 7, 2003

Cross-site scripting (XSS) vulnerability in viewtopic.php for phpBB allows remote attackers to insert arbitrary web script via the topic_id parameter.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0486

Published Aug 7, 2003

SQL injection vulnerability in viewtopic.php for phpBB 2.0.5 and earlier allows remote attackers to steal password hashes via the topic_id parameter.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1537

Published Mar 31, 2003

admin_ug_auth.php in phpBB 2.0.0 allows local users to gain administrator privileges by directly calling admin_ug_auth.php with modifed form fields such as "u".

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2002-1707

Published Dec 31, 2002

install.php in phpBB 2.0 through 2.0.1, when "allow_url_fopen" and "register_globals" variables are set to "on", allows remote attackers to execute arbitrary PHP code by modifying…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1894

Published Dec 31, 2002

Cross-site scripting (XSS) vulnerability in viewtopic.php in phpBB 2.0.3 allows remote attackers to inject arbitrary web script or HTML via the highlight parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 51-75 of 82 CVEsPage 3 of 4