CVE-2005-3415
- EPSS 1.08%
- Published 01.11.2005 21:02:00
- Last modified 03.04.2025 01:03:51
phpBB 2.0.17 and earlier allows remote attackers to bypass protection mechanisms that deregister global variables by setting both a GET/POST/COOKIE (GPC) variable and a GLOBALS[] variable with the same name, which causes phpBB to unset the GLOBALS[] ...
CVE-2005-3416
- EPSS 0.84%
- Published 01.11.2005 21:02:00
- Last modified 03.04.2025 01:03:51
phpBB 2.0.17 and earlier, when register_globals is enabled and the session_start function has not been called to handle a session, allows remote attackers to bypass security checks by setting the $_SESSION and $HTTP_SESSION_VARS variables to strings ...
CVE-2005-3417
- EPSS 0.84%
- Published 01.11.2005 21:02:00
- Last modified 03.04.2025 01:03:51
phpBB 2.0.17 and earlier, when the register_long_arrays directive is disabled, allows remote attackers to modify global variables and bypass security mechanisms because PHP does not define the associated HTTP_* variables.
CVE-2005-3418
- EPSS 1.45%
- Published 01.11.2005 21:02:00
- Last modified 03.04.2025 01:03:51
Multiple cross-site scripting (XSS) vulnerabilities in phpBB 2.0.17 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) error_msg parameter to usercp_register.php, (2) forward_page parameter to login.php, and (3) lis...
CVE-2005-3419
- EPSS 1.31%
- Published 01.11.2005 21:02:00
- Last modified 03.04.2025 01:03:51
SQL injection vulnerability in usercp_register.php in phpBB 2.0.17 allows remote attackers to execute arbitrary SQL commands via the signature_bbcode_uid parameter, which is not properly initialized.
CVE-2005-3310
- EPSS 0.54%
- Published 26.10.2005 01:02:00
- Last modified 03.04.2025 01:03:51
Interpretation conflict in phpBB 2.0.17, with remote avatars and avatar uploading enabled, allows remote authenticated users to inject arbitrary web script or HTML via an HTML file with a GIF or JPEG file extension, which causes the HTML to be execut...
CVE-2005-2161
- EPSS 0.34%
- Published 06.07.2005 04:00:00
- Last modified 03.04.2025 01:03:51
Cross-site scripting (XSS) vulnerability in phpBB 2.0.16 allows remote attackers to inject arbitrary web script or HTML via nested [url] tags.
CVE-2005-2086
- EPSS 86.51%
- Published 05.07.2005 04:00:00
- Last modified 03.04.2025 01:03:51
PHP remote file inclusion vulnerability in viewtopic.php in phpBB 2.0.15 and earlier allows remote attackers to execute arbitrary PHP code.
CVE-2005-1193
- EPSS 27.11%
- Published 16.05.2005 04:00:00
- Last modified 03.04.2025 01:03:51
The bbencode_second_pass and make_clickable functions in bbcode.php for phpBB before 2.0.15, as used in viewtopic.php, privmsg.php, and other scripts, allow remote attackers to execute arbitrary script via a BBcode tag with a (1) javascript:, (2) app...
CVE-2005-1196
- EPSS 0.33%
- Published 02.05.2005 04:00:00
- Last modified 03.04.2025 01:03:51
SQL injection vulnerability in kb.php in the Knowledge Base module for phpBB allows remote attackers to obtain sensitive information and execute SQL commands via the cat parameter.