Vulnerabilities (CVE)

Filtered by vendor Fluxbb Subscribe
Filtered by product Fluxbb
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2014-10029 1 Fluxbb 1 Fluxbb 2017-09-08 7.5 HIGH N/A
SQL injection vulnerability in profile.php in FluxBB before 1.4.13 and 1.5.x before 1.5.7 allows remote attackers to execute arbitrary SQL commands via the req_new_email parameter.
CVE-2014-9574 1 Fluxbb 1 Fluxbb 2017-09-08 9.3 HIGH N/A
Directory traversal vulnerability in install.php in FluxBB before 1.5.8 allows remote attackers to include and execute arbitrary local install.php files via a .. (dot dot) in the install_lang parameter.
CVE-2014-10030 1 Fluxbb 1 Fluxbb 2015-01-14 5.8 MEDIUM N/A
Open redirect vulnerability in forums/login.php in FluxBB before 1.4.13 and 1.5.x before 1.5.7 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect_url parameter.