CVE-2008-4431
- EPSS 0.4%
- Veröffentlicht 03.10.2008 22:22:45
- Zuletzt bearbeitet 09.04.2025 00:30:58
SQL injection vulnerability in index.php in IceBB 1.0-rc9.3 and earlier allows remote attackers to execute arbitrary SQL commands via the skin parameter, probably related to an incorrect protection mechanism in the clean_string function in includes/f...
CVE-2008-3416
- EPSS 0.8%
- Veröffentlicht 31.07.2008 17:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
SQL injection vulnerability in modules/members.php in IceBB before 1.0-rc9.3 allows remote attackers to execute arbitrary SQL commands via the username parameter in a members action to index.php, related to an incorrect protection mechanism in the cl...
CVE-2007-6083
- EPSS 2.23%
- Veröffentlicht 22.11.2007 00:46:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
SQL injection vulnerability in admin/index.php in IceBB 1.0-rc6 allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For HTTP header.
CVE-2007-1725
- EPSS 0.73%
- Veröffentlicht 28.03.2007 10:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
SQL injection vulnerability in index.php in IceBB 1.0-rc5 allows remote authenticated users to execute arbitrary SQL commands via the filename of an uploaded file to the avatar function, as demonstrated by setting admin privileges.
CVE-2007-1726
- EPSS 9.26%
- Veröffentlicht 28.03.2007 10:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Unrestricted file upload vulnerability in index.php in IceBB 1.0-rc5 allows remote authenticated users to upload arbitrary files via the avatar function, which can later be accessed in uploads/.