Woltlab

Burning Board

31 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.34%
  • Published 28.06.2006 01:45:00
  • Last modified 03.04.2025 01:03:51

SQL injection vulnerability in report.php in Woltlab Burning Board (WBB) 2.3.1 allows remote attackers to execute arbitrary SQL commands via the postid parameter.

Exploit
  • EPSS 0.46%
  • Published 28.06.2006 01:45:00
  • Last modified 03.04.2025 01:03:51

SQL injection vulnerability in showmods.php in Woltlab Burning Board (WBB) 1.2 allows remote attackers to execute arbitrary SQL commands via the boardid parameter.

Exploit
  • EPSS 0.46%
  • Published 28.06.2006 01:45:00
  • Last modified 03.04.2025 01:03:51

SQL injection vulnerability in newthread.php in Woltlab Burning Board (WBB) 2.0 RC2 allows remote attackers to execute arbitrary SQL commands via the boardid parameter.

  • EPSS 0.49%
  • Published 24.06.2006 10:06:00
  • Last modified 03.04.2025 01:03:51

SQL injection vulnerability in profile.php in Woltlab Burning Board (WBB) 2.1.6 allows remote attackers to execute arbitrary SQL commands via the userid parameter.

  • EPSS 0.49%
  • Published 24.06.2006 10:06:00
  • Last modified 03.04.2025 01:03:51

SQL injection vulnerability in studienplatztausch.php in Woltlab Burning Board (WBB) 2.2.1 allows remote attackers to execute arbitrary SQL commands via the sid parameter.

  • EPSS 0.49%
  • Published 24.06.2006 10:06:00
  • Last modified 03.04.2025 01:03:51

SQL injection vulnerability in thread.php in Woltlab Burning Board (WBB) 2.2.2 allows remote attackers to execute arbitrary SQL commands via the threadid parameter.

  • EPSS 0.5%
  • Published 03.06.2006 01:02:00
  • Last modified 03.04.2025 01:03:51

SQL injection vulnerability in misc.php in Woltlab Burning Board (WBB) 2.3.4 allows remote attackers to execute arbitrary SQL commands via the sid parameter.

Exploit
  • EPSS 1.03%
  • Published 24.05.2006 23:02:00
  • Last modified 03.04.2025 01:03:51

SQL injection vulnerability in links.php in 4R Linklist 1.0 RC2 and earlier, a module for Woltlab Burning Board, allows remote attackers to execute arbitrary SQL commands via the cat parameter.

  • EPSS 12.77%
  • Published 21.03.2006 01:06:00
  • Last modified 03.04.2025 01:03:51

Cross-site scripting (XSS) vulnerability in acp/lib/class_db_mysql.php in Woltlab Burning Board (wBB) 2.3.4 allows remote attackers to inject arbitrary web script or HTML via the errormsg parameter when a SQL error is generated.

Exploit
  • EPSS 0.42%
  • Published 14.03.2006 02:02:00
  • Last modified 03.04.2025 01:03:51

Cross-site scripting (XSS) vulnerability in misc.php in Woltlab Burning Board (wBB) 2.3.4 allows remote attackers to inject arbitrary web script or HTML via the percent parameter. NOTE: this issue has been disputed in a followup post, although the o...