- EPSS 0.28%
- Veröffentlicht 23.09.2011 23:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
DeluxeBB 1.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by header_html.php.
CVE-2010-4151
- EPSS 1.42%
- Veröffentlicht 03.11.2010 20:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
SQL injection vulnerability in misc.php in DeluxeBB 1.3, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the xthedateformat parameter in a register action, a different vector than...
CVE-2010-1859
- EPSS 0.1%
- Veröffentlicht 07.05.2010 23:00:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
SQL injection vulnerability in newpost.php in DeluxeBB 1.3 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the membercookie cookie when adding a new thread.
CVE-2009-4468
- EPSS 0.72%
- Veröffentlicht 30.12.2009 20:00:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in misc.php in DeluxeBB 1.3 allows remote attackers to inject arbitrary web script or HTML via the page parameter.
- EPSS 0.83%
- Veröffentlicht 30.12.2009 20:00:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
misc.php in DeluxeBB 1.3 allows remote attackers to register accounts without a valid email address via a valemail action with the valmem set to a pre-assigned user ID, which is visible from a memberlist action.
- EPSS 1.5%
- Veröffentlicht 30.12.2009 20:00:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
DeluxeBB 1.3 allows remote attackers to obtain sensitive information via a crafted page parameter to misc.php, which reveals the installation path in an error message. NOTE: this issue might be resultant from improperly controlled computation in too...
CVE-2009-4465
- EPSS 1.58%
- Veröffentlicht 30.12.2009 20:00:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
DeluxeBB 1.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain user and configuration information, log data, and gain administrative access via a direct request to scripts in (1)...
CVE-2009-1033
- EPSS 0.36%
- Veröffentlicht 20.03.2009 18:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
SQL injection vulnerability in misc.php in DeluxeBB 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the qorder parameter, a different vector than CVE-2005-2989 and CVE-2006-2503.
CVE-2008-6146
- EPSS 0.38%
- Veröffentlicht 16.02.2009 17:30:04
- Zuletzt bearbeitet 09.04.2025 00:30:58
SQL injection vulnerability in pm.php in DeluxeBB 1.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via a delete##### parameter in a Delete action, a different vector than CVE-2005-2989.
CVE-2008-2195
- EPSS 3.03%
- Veröffentlicht 14.05.2008 17:20:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Static code injection vulnerability in admincp.php in DeluxeBB 1.2 and earlier allows remote authenticated administrators to inject arbitrary PHP code into logs/cp.php via the URI.