CVE-2006-3256
- EPSS 0.34%
- Published 28.06.2006 01:45:00
- Last modified 03.04.2025 01:03:51
SQL injection vulnerability in report.php in Woltlab Burning Board (WBB) 2.3.1 allows remote attackers to execute arbitrary SQL commands via the postid parameter.
CVE-2006-3255
- EPSS 0.46%
- Published 28.06.2006 01:45:00
- Last modified 03.04.2025 01:03:51
SQL injection vulnerability in showmods.php in Woltlab Burning Board (WBB) 1.2 allows remote attackers to execute arbitrary SQL commands via the boardid parameter.
CVE-2006-3254
- EPSS 0.46%
- Published 28.06.2006 01:45:00
- Last modified 03.04.2025 01:03:51
SQL injection vulnerability in newthread.php in Woltlab Burning Board (WBB) 2.0 RC2 allows remote attackers to execute arbitrary SQL commands via the boardid parameter.
CVE-2006-3218
- EPSS 0.49%
- Published 24.06.2006 10:06:00
- Last modified 03.04.2025 01:03:51
SQL injection vulnerability in profile.php in Woltlab Burning Board (WBB) 2.1.6 allows remote attackers to execute arbitrary SQL commands via the userid parameter.
CVE-2006-3220
- EPSS 0.49%
- Published 24.06.2006 10:06:00
- Last modified 03.04.2025 01:03:51
SQL injection vulnerability in studienplatztausch.php in Woltlab Burning Board (WBB) 2.2.1 allows remote attackers to execute arbitrary SQL commands via the sid parameter.
CVE-2006-3219
- EPSS 0.49%
- Published 24.06.2006 10:06:00
- Last modified 03.04.2025 01:03:51
SQL injection vulnerability in thread.php in Woltlab Burning Board (WBB) 2.2.2 allows remote attackers to execute arbitrary SQL commands via the threadid parameter.
CVE-2006-2792
- EPSS 0.5%
- Published 03.06.2006 01:02:00
- Last modified 03.04.2025 01:03:51
SQL injection vulnerability in misc.php in Woltlab Burning Board (WBB) 2.3.4 allows remote attackers to execute arbitrary SQL commands via the sid parameter.
CVE-2006-2569
- EPSS 1.03%
- Published 24.05.2006 23:02:00
- Last modified 03.04.2025 01:03:51
SQL injection vulnerability in links.php in 4R Linklist 1.0 RC2 and earlier, a module for Woltlab Burning Board, allows remote attackers to execute arbitrary SQL commands via the cat parameter.
CVE-2006-1324
- EPSS 12.77%
- Published 21.03.2006 01:06:00
- Last modified 03.04.2025 01:03:51
Cross-site scripting (XSS) vulnerability in acp/lib/class_db_mysql.php in Woltlab Burning Board (wBB) 2.3.4 allows remote attackers to inject arbitrary web script or HTML via the errormsg parameter when a SQL error is generated.
CVE-2006-1215
- EPSS 0.42%
- Published 14.03.2006 02:02:00
- Last modified 03.04.2025 01:03:51
Cross-site scripting (XSS) vulnerability in misc.php in Woltlab Burning Board (wBB) 2.3.4 allows remote attackers to inject arbitrary web script or HTML via the percent parameter. NOTE: this issue has been disputed in a followup post, although the o...