Pbboard

Pbboard

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 2.42%
  • Veröffentlicht 05.12.2014 15:59:08
  • Zuletzt bearbeitet 12.04.2025 10:46:40

SQL injection vulnerability in the CheckEmail function in includes/functions.class.php in PBBoard 3.0.1 before 20141128 allows remote attackers to execute arbitrary SQL commands via the email parameter in the register page to index.php. NOTE: the em...

Exploit
  • EPSS 5.21%
  • Veröffentlicht 27.08.2012 23:55:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Unrestricted file upload vulnerability in admin.php in PBBoard 2.1.4 allows remote administrators to execute arbitrary PHP code by uploading a file with an executable extension, then accessing it via a direct request to the file in the addons directo...

Exploit
  • EPSS 0.31%
  • Veröffentlicht 12.08.2012 00:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Multiple SQL injection vulnerabilities in PBBoard 2.1.4 allow remote attackers to execute arbitrary SQL commands via the (1) username parameter to the send page, (2) email parameter to the forget page, (3) password parameter to the forum_archive page...

Exploit
  • EPSS 5.22%
  • Veröffentlicht 12.08.2012 00:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The new_password page in PBBoard 2.1.4 allows remote attackers to change the password of arbitrary user accounts via the member_id and new_password parameters to index.php.

Exploit
  • EPSS 0.12%
  • Veröffentlicht 21.02.2012 13:31:21
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Multiple cross-site request forgery (CSRF) vulnerabilities in admin.php in PBBoard 2.1.4 allow remote attackers to hijack the authentication of administrators for requests that (1) upload a file via an add action or (2) change the contents of a file ...

  • EPSS 0.23%
  • Veröffentlicht 09.10.2009 14:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Cross-site scripting (XSS) vulnerability in forums/index.php in Power Bulletin Board (PBBoard) 2.0.2 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the id parameter in a new_topic action.