Woltlab

Burning Board

31 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.08%
  • Published 09.09.2009 19:30:00
  • Last modified 09.04.2025 00:30:58

Cross-site request forgery (CSRF) vulnerability in index.php in WoltLab Burning Board (wBB) 3.0.1, and possibly other 3.x versions, allows remote attackers to hijack the authentication of users for requests that delete private messages via the pmID p...

  • EPSS 0.52%
  • Published 09.04.2008 21:05:00
  • Last modified 09.04.2025 00:30:58

WoltLab Community Framework (WCF) 1.0.6 in WoltLab Burning Board 3.0.5 allows remote attackers to obtain the full path via invalid (1) page and (2) form parameters, which leaks the path from an exception handler when a valid class cannot be found.

  • EPSS 0.48%
  • Published 09.04.2008 21:05:00
  • Last modified 09.04.2025 00:30:58

Cross-site scripting (XSS) vulnerability in WoltLab Community Framework (WCF) 1.0.6 in WoltLab Burning Board 3.0.5 allows remote attackers to inject arbitrary web script or HTML via the (1) page and (2) form parameters, which are not properly handled...

Exploit
  • EPSS 0.39%
  • Published 21.02.2008 00:44:00
  • Last modified 09.04.2025 00:30:58

SQL injection vulnerability in index.php in WoltLab Burning Board 3.0.3 PL 1 allows remote attackers to execute arbitrary SQL commands via the sortOrder parameter to the PMList page.

  • EPSS 0.15%
  • Published 29.01.2008 20:00:00
  • Last modified 09.04.2025 00:30:58

Cross-site request forgery (CSRF) vulnerability in modcp.php in Woltlab Burning Board (wBB) 2.3.6 PL2 allows remote attackers to delete threads as moderators or administrators via a thread_del action.

  • EPSS 0.3%
  • Published 20.03.2007 20:19:00
  • Last modified 09.04.2025 00:30:58

SQL injection vulnerability in usergroups.php in Woltlab Burning Board (wBB) 2.x allows remote attackers to execute arbitrary SQL commands via the array index of the applicationids array.

  • EPSS 0.58%
  • Published 14.03.2007 00:19:00
  • Last modified 09.04.2025 00:30:58

Multiple cross-site scripting (XSS) vulnerabilities in register.php in Woltlab Burning Board (wBB) 2.3.6 and Burning Board Lite 1.0.2pl3e allow remote attackers to inject arbitrary web script or HTML via the (1) r_username, (2) r_email, (3) r_passwor...

  • EPSS 0.58%
  • Published 19.01.2007 23:28:00
  • Last modified 09.04.2025 00:30:58

SQL injection vulnerability in search.php in Woltlab Burning Board (wBB) 1.0.2 and earlier, and 2.3.6 and earlier in the 2.x series, allows remote attackers to execute arbitrary SQL commands via the boardids[1] and other boardids[] parameters.

  • EPSS 0.48%
  • Published 27.09.2006 23:07:00
  • Last modified 09.04.2025 00:30:58

SQL injection vulnerability in thread.php in WoltLab Burning Board (wBB) 2.3.x allows remote attackers to obtain the version numbers of PHP, MySQL, and wBB via the page parameter. NOTE: this issue might be a forced SQL error. Also, the original repo...

Exploit
  • EPSS 1.49%
  • Published 24.08.2006 01:04:00
  • Last modified 03.04.2025 01:03:51

Cross-site scripting (XSS) vulnerability in attachment.php in WoltLab Burning Board (WBB) 2.3.5 allows remote attackers to inject arbitrary web script or HTML via a GIF image that contains URL-encoded Javascript.