Phpbb Group

Phpbb

81 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.75%
  • Veröffentlicht 06.02.2006 22:02:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Cross-site request forgery (CSRF) vulnerability in phpBB 2.0.19, when Link to off-site Avatar or bbcode (IMG) are enabled, allows remote attackers to perform unauthorized actions as a logged in user via a link or IMG tag in a user profile, as demonst...

Exploit
  • EPSS 0.75%
  • Veröffentlicht 06.02.2006 22:02:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Cross-site scripting (XSS) vulnerability in admin_smilies.php in phpBB 2.0.19 allows remote attackers to inject arbitrary web script or HTML via Javascript events such as "onmouseover" in the (1) smile_url or (2) smile_emotion parameters, which bypas...

Exploit
  • EPSS 6.03%
  • Veröffentlicht 27.01.2006 00:03:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

phpBB 2.0.19 and earlier allows remote attackers to cause a denial of service (application crash) by (1) registering many users through profile.php or (2) using search.php to search in a certain way that confuses the database.

Exploit
  • EPSS 0.41%
  • Veröffentlicht 05.01.2006 19:03:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Cross-site scripting (XSS) vulnerability in phpBB 2.0.19, when "Allowed HTML tags" is enabled, allows remote attackers to inject arbitrary web script or HTML via a permitted HTML tag with ' (single quote) characters and active attributes such as onmo...

  • EPSS 0.38%
  • Veröffentlicht 22.12.2005 23:03:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

A "missing request validation" error in phpBB 2 before 2.0.18 allows remote attackers to edit private messages of other users, probably by modifying certain parameters or other inputs.

  • EPSS 0.5%
  • Veröffentlicht 22.12.2005 23:03:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

SQL injection vulnerability in phpBB 2 before 2.0.18 allows remote attackers to execute arbitrary SQL commands via the topic type.

  • EPSS 1.26%
  • Veröffentlicht 20.12.2005 01:03:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

admin/admin_disallow.php in phpBB 2.0.18 allows remote attackers to obtain the installation path via a direct request with a non-empty setmodules parameter, which causes an invalid append_sid function call that leaks the path in an error message.

Exploit
  • EPSS 1.42%
  • Veröffentlicht 20.12.2005 01:03:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Cross-site scripting (XSS) vulnerability in phpBB 2.0.18, when "Allowed HTML tags" is enabled, allows remote attackers to inject arbitrary Javascript via a permitted HTML tag with " (quote) characters and active attributes such as onmouseover.

Exploit
  • EPSS 0.46%
  • Veröffentlicht 24.11.2005 11:03:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

phpBB 2.0.18 allows remote attackers to obtain sensitive information via a large SQL query, which generates an error message that reveals SQL syntax or the full installation path.

  • EPSS 2.32%
  • Veröffentlicht 01.11.2005 21:02:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

usercp_register.php in phpBB 2.0.17 allows remote attackers to modify regular expressions and execute PHP code via the signature_bbcode_uid parameter, as demonstrated by injecting an "e" modifier into a preg_replace statement.