Vulnerabilities (CVE)

Filtered by vendor Phpbb Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-6506 1 Phpbb 1 Phpbb 2017-08-17 5.0 MEDIUM N/A
Unspecified vulnerability in phpBB before 3.0.4 allows attackers to bypass intended access restrictions and activate de-activated accounts via unknown vectors.
CVE-2008-4125 1 Phpbb 1 Phpbb 2017-08-08 5.0 MEDIUM N/A
The search function in phpBB 2.x provides a search_id value that leaks the state of PHP's PRNG, which allows remote attackers to obtain potentially sensitive information, as demonstrated by a cross-application attack against WordPress, a different vulnerability than CVE-2006-0632.
CVE-2008-3224 1 Phpbb 1 Phpbb 2017-08-08 10.0 HIGH N/A
Unspecified vulnerability in phpBB before 3.0.1 has unknown impact and attack vectors related to "urls gone through redirect() being used within login_box()."
CVE-2008-1766 1 Phpbb 1 Phpbb 2017-08-08 10.0 HIGH N/A
Multiple unspecified vulnerabilities in phpBB before 3.0.1 have unknown impact and attack vectors, related to "two minor security-related bugs."
CVE-2002-2287 1 Phpbb 1 Advanced Quick Reply Hack 2017-07-29 7.5 HIGH N/A
PHP remote file inclusion vulnerability in quick_reply.php for phpBB Advanced Quick Reply Hack 1.0.0 and 1.1.0 allows remote attackers to execute arbitrary PHP code via the phpbb_root_path parameter.
CVE-2002-2255 1 Phpbb 1 Phpbb 2017-07-29 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in search.php in phpBB 2.0.3 and possibly earlier versions allows remote attackers to inject arbitrary web script or HTML via the search_username parameter in searchuser mode.
CVE-2006-2220 1 Phpbb 1 Phpbb 2017-07-20 5.0 MEDIUM N/A
phpBB 2.0.20 does not properly verify user-specified input variables used as limits to SQL queries, which allows remote attackers to obtain sensitive information via a negative LIMIT specification, as demonstrated by the start parameter to memberlist.php, which reveals the SQL query in the resulting error message.
CVE-2007-5100 1 Phpbb 1 Phpbb Plus 2011-03-08 6.8 MEDIUM N/A
Multiple PHP remote file inclusion vulnerabilities in phpBB Plus 1.53, and 1.53a before 20070922, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter to (1) language/lang_german/lang_admin_album.php, (2) language/lang_english/lang_main_album.php, and (3) language/lang_english/lang_admin_album.php, different vectors than CVE-2007-5009.
CVE-2010-1627 1 Phpbb 1 Phpbb 2010-05-20 4.3 MEDIUM N/A
feed.php in phpBB 3.0.7 before 3.0.7-PL1 does not properly check permissions for feeds, which allows remote attackers to bypass intended access restrictions via unspecified attack vectors related to permission settings on a private forum.
CVE-2010-1630 1 Phpbb 1 Phpbb 2010-05-20 7.5 HIGH N/A
Unspecified vulnerability in posting.php in phpBB before 3.0.5 has unknown impact and attack vectors related to the use of a "forum id" in circumstances related to a "global announcement."
CVE-2008-6507 1 Phpbb 1 Phpbb 2009-03-24 5.0 MEDIUM N/A
Unspecified vulnerability in phpBB before 3.0.4 allows attackers to obtain sensitive information via unknown vectors related to the lack of password prompts for a private message that quotes a post in a password-protected forum.
CVE-2002-2346 1 Phpbb 1 Phpbb 2008-09-05 5.0 MEDIUM N/A
phpBB 2.0 through 2.0.3 generates names for uploaded avatar files with the hex-encoded IP address of the client system, which allows remote attackers to obtain client IP addresses.
CVE-2002-2349 1 Phpbb 1 Phpbbmod 2008-09-05 5.0 MEDIUM N/A
phpinfo.php in phpBBmod 1.3.3 executes the phpinfo function, which allows remote attackers to obtain sensitive environment information.