Phpbb Group

Phpbb

81 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 4.79%
  • Published 30.08.2006 01:04:00
  • Last modified 03.04.2025 01:03:51

usercp_avatar.php in PHPBB 2.0.20, when avatar uploading is enabled, allows remote attackers to use the server as a web proxy by submitting a URL to the avatarurl parameter, which is then used in an HTTP GET request.

Exploit
  • EPSS 4.35%
  • Published 06.06.2006 20:06:00
  • Last modified 03.04.2025 01:03:51

PHP remote file inclusion vulnerability in template.php in phpBB 2 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. NOTE: followup posts have disputed this issue, stating that template.php does not appear in php...

  • EPSS 0.56%
  • Published 15.05.2006 16:06:00
  • Last modified 03.04.2025 01:03:51

SQL injection vulnerability in charts.php in the Chart mod for phpBB allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • EPSS 0.56%
  • Published 15.05.2006 16:06:00
  • Last modified 03.04.2025 01:03:51

Cross-site scripting (XSS) vulnerability in charts.php in the Chart mod for phpBB allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: this issue might be resultant from SQL injection.

Exploit
  • EPSS 6.32%
  • Published 02.05.2006 10:02:00
  • Last modified 03.04.2025 01:03:51

PHP remote file inclusion vulnerability in /includes/kb_constants.php in Knowledge Base Mod for PHPbb 2.0.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.

  • EPSS 1.32%
  • Published 20.04.2006 10:02:00
  • Last modified 03.04.2025 01:03:51

Unspecified vulnerability in phpBB allows remote authenticated users with Administration Panel access to execute arbitrary PHP code via crafted Font Colour 3 ($theme[fontcolor3] variable) and/or signature values, possibly involving the highlight func...

Exploit
  • EPSS 0.37%
  • Published 20.04.2006 10:02:00
  • Last modified 03.04.2025 01:03:51

Direct static code injection vulnerability in includes/template.php in phpBB allows remote authenticated users with write access to execute arbitrary PHP code by modifying a template in a way that (1) bypasses a loose ".*" regular expression to match...

  • EPSS 0.43%
  • Published 13.04.2006 10:02:00
  • Last modified 03.04.2025 01:03:51

Multiple cross-site scripting (XSS) vulnerabilities in phpBB 2.0.19 allow remote attackers to inject arbitrary web script or HTML via the (1) Site Description field in (a) admin_board.php, the (2) Group name and (3) Group description fields in (b) ad...

  • EPSS 0.53%
  • Published 04.04.2006 10:04:00
  • Last modified 03.04.2025 01:03:51

Cross-site scripting (XSS) vulnerability in profile.php in phpBB 2.0.19 allows remote attackers to inject arbitrary web script or HTML via the cur_password parameter. NOTE: the provenance of this information is unknown; the details are obtained sole...

Exploit
  • EPSS 0.98%
  • Published 10.02.2006 11:02:00
  • Last modified 03.04.2025 01:03:51

The gen_rand_string function in phpBB 2.0.19 uses insufficiently random data (small value space) to create the activation key ("validation ID") that is sent by e-mail when establishing a password, which makes it easier for remote attackers to obtain ...