Skip to main content

Vendor/product archive

ubbcentral / ubb.threads CVEs

Beta · best-effort

20 CVEs tagged to ubbcentral / ubb.threads0 Critical, 7 High, 13 Medium, 0 Low, 0 Unrated.

CVE-2012-5104

Published Sep 23, 2012

Cross-site scripting (XSS) vulnerability in forums/ubbthreads.php in UBB.threads 7.5.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the Loginname…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-6970

Published Aug 13, 2009

SQL injection vulnerability in dosearch.inc.php in UBB.threads 7.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the Forum[] array parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-1956

Published Apr 11, 2007

SQL injection vulnerability in ubbthreads.php in Groupee UBB.threads 6.1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the C parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-5136

Published Oct 3, 2006

Multiple PHP remote file inclusion vulnerabilities in ubbt.inc.php in Groupee UBB.threads 6.5.1.1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) GLOBALS…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-5137

Published Oct 3, 2006

Multiple direct static code injection vulnerabilities in Groupee UBB.threads 6.5.1.1 allow remote attackers to (1) inject PHP code via a theme[] array parameter to admin/doeditthe…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-5138

Published Oct 3, 2006

Groupee UBB.threads 6.5.1.1 allows remote attackers to obtain sensitive information via a direct request for cron/php/subscriptions.php, which reveals the path in an error message.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-2755

Published Jun 2, 2006

Cross-site scripting (XSS) vulnerability in index.php in UBBThreads 5.x and earlier allows remote attackers to inject arbitrary web script or HTML via the debug parameter, as demo…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-2675

Published May 30, 2006

PHP remote file inclusion vulnerability in ubbt.inc.php in UBBThreads 5.x and 6.x allows remote attackers to execute arbitrary PHP code via a URL in the (1) thispath or (2) config…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-2568

Published May 24, 2006

PHP remote file inclusion vulnerability in addpost_newpoll.php in UBB.threads 6.4 through 6.5.2 and 6.5.1.1 (trial) allows remote attackers to execute arbitrary PHP code via a URL…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1423

Published Mar 28, 2006

SQL injection vulnerability in showflat.php in UBB.threads 5.5.1, 6.0 br5, 6.0.1, 6.0.2, and earlier, allows remote attackers to execute arbitrary SQL commands via the Number para…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0545

Published Feb 4, 2006

SQL injection vulnerability in showflat.php in Groupee (formerly known as Infopop) UBB.threads 6.3 and earlier allows remote attackers to execute arbitrary SQL commands via the Nu…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-2057

Published Jun 29, 2005

Multiple cross-site scripting (XSS) vulnerabilities in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to inject arbitrary web script or HTML via the (1) Searchpage p…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-2058

Published Jun 29, 2005

Multiple SQL injection vulnerabilities in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to execute arbitrary SQL commands via the Number parameter to (1) download.p…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-2059

Published Jun 29, 2005

Multiple cross-site request forgery (CSRF) vulnerabilities in (1) addaddress.php, (2) toggleignore.php, (3) removeignore.php, and (4) removeaddress.php in Infopop UBB.Threads befo…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-2060

Published Jun 29, 2005

Multiple HTTP Response Splitting vulnerabilities in (1) toggleshow.php, (2) togglecats.php, and (3) showprofile.php in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-2061

Published Jun 29, 2005

Infopop UBB.Threads before 6.5.2 Beta allows remote attackers to include arbitrary files via the language parameter in a cookie followed by a null (%00) byte.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0726

Published May 2, 2005

SQL injection vulnerability in editpost.php in UBB.threads 6.0 allows remote attackers to execute arbitrary SQL commands via the Number parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-2509

Published Dec 31, 2004

Cross-site scripting (XSS) vulnerabilities in (1) calendar.php, (2) login.php, and (3) online.php in Infopop UBB.Threads 6.2.3 and 6.5 allow remote attackers to inject arbitrary w…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2510

Published Dec 31, 2004

Cross-site scripting (XSS) vulnerability in showflat.php in Infopop UBB.Threads before 6.5 allows remote attackers to inject arbitrary web script or HTML via the Cat parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1622

Published Oct 21, 2004

SQL injection vulnerability in dosearch.php in UBB.threads 3.4.x allows remote attackers to execute arbitrary SQL statements via the Name parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-20 of 20 CVEsPage 1 of 1