Deluxebb

Deluxebb

29 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.28%
  • Veröffentlicht 23.09.2011 23:55:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

DeluxeBB 1.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by header_html.php.

Exploit
  • EPSS 1.42%
  • Veröffentlicht 03.11.2010 20:00:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

SQL injection vulnerability in misc.php in DeluxeBB 1.3, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the xthedateformat parameter in a register action, a different vector than...

Exploit
  • EPSS 0.1%
  • Veröffentlicht 07.05.2010 23:00:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

SQL injection vulnerability in newpost.php in DeluxeBB 1.3 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the membercookie cookie when adding a new thread.

Exploit
  • EPSS 0.72%
  • Veröffentlicht 30.12.2009 20:00:01
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Cross-site scripting (XSS) vulnerability in misc.php in DeluxeBB 1.3 allows remote attackers to inject arbitrary web script or HTML via the page parameter.

Exploit
  • EPSS 0.83%
  • Veröffentlicht 30.12.2009 20:00:01
  • Zuletzt bearbeitet 09.04.2025 00:30:58

misc.php in DeluxeBB 1.3 allows remote attackers to register accounts without a valid email address via a valemail action with the valmem set to a pre-assigned user ID, which is visible from a memberlist action.

Exploit
  • EPSS 1.5%
  • Veröffentlicht 30.12.2009 20:00:01
  • Zuletzt bearbeitet 09.04.2025 00:30:58

DeluxeBB 1.3 allows remote attackers to obtain sensitive information via a crafted page parameter to misc.php, which reveals the installation path in an error message. NOTE: this issue might be resultant from improperly controlled computation in too...

Exploit
  • EPSS 1.58%
  • Veröffentlicht 30.12.2009 20:00:01
  • Zuletzt bearbeitet 09.04.2025 00:30:58

DeluxeBB 1.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain user and configuration information, log data, and gain administrative access via a direct request to scripts in (1)...

Exploit
  • EPSS 0.36%
  • Veröffentlicht 20.03.2009 18:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

SQL injection vulnerability in misc.php in DeluxeBB 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the qorder parameter, a different vector than CVE-2005-2989 and CVE-2006-2503.

Exploit
  • EPSS 0.38%
  • Veröffentlicht 16.02.2009 17:30:04
  • Zuletzt bearbeitet 09.04.2025 00:30:58

SQL injection vulnerability in pm.php in DeluxeBB 1.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via a delete##### parameter in a Delete action, a different vector than CVE-2005-2989.

  • EPSS 3.03%
  • Veröffentlicht 14.05.2008 17:20:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Static code injection vulnerability in admincp.php in DeluxeBB 1.2 and earlier allows remote authenticated administrators to inject arbitrary PHP code into logs/cp.php via the URI.