Phpbb

Phpbb

35 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.54%
  • Published 23.03.2009 16:30:00
  • Last modified 09.04.2025 00:30:58

Unspecified vulnerability in phpBB before 3.0.4 allows attackers to bypass intended access restrictions and activate de-activated accounts via unknown vectors.

  • EPSS 0.22%
  • Published 18.09.2008 17:59:33
  • Last modified 09.04.2025 00:30:58

The search function in phpBB 2.x provides a search_id value that leaks the state of PHP's PRNG, which allows remote attackers to obtain potentially sensitive information, as demonstrated by a cross-application attack against WordPress, a different vu...

  • EPSS 0.32%
  • Published 18.07.2008 16:41:00
  • Last modified 09.04.2025 00:30:58

Unspecified vulnerability in phpBB before 3.0.1 has unknown impact and attack vectors related to "urls gone through redirect() being used within login_box()."

  • EPSS 0.32%
  • Published 12.04.2008 20:05:00
  • Last modified 09.04.2025 00:30:58

Multiple unspecified vulnerabilities in phpBB before 3.0.1 have unknown impact and attack vectors, related to "two minor security-related bugs."

  • EPSS 0.24%
  • Published 29.01.2008 20:00:00
  • Last modified 09.04.2025 00:30:58

Cross-site request forgery (CSRF) vulnerability in privmsg.php in phpBB 2.0.22 allows remote attackers to delete private messages (PM) as arbitrary users via a deleteall action.

Exploit
  • EPSS 0.37%
  • Published 29.10.2007 19:46:00
  • Last modified 09.04.2025 00:30:58

Multiple SQL injection vulnerabilities in directory.php in the Multi-Forums (aka Multi Host Forum Pro) module 1.3.3, for phpBB and Invision Power Board (IPB or IP.Board), allow remote attackers to execute arbitrary SQL commands via the (1) go and (2)...

Exploit
  • EPSS 1.65%
  • Published 03.10.2007 14:17:00
  • Last modified 09.04.2025 00:30:58

PHP remote file inclusion vulnerability in includes/openid/Auth/OpenID/BBStore.php in phpBB Openid 0.2.0 allows remote attackers to execute arbitrary PHP code via a URL in the openid_root_path parameter.

  • EPSS 0.39%
  • Published 04.09.2007 22:17:00
  • Last modified 09.04.2025 00:30:58

SQL injection vulnerability in links.php in the Links MOD 1.2.2 and earlier for phpBB 2.0.22 and earlier allows remote attackers to execute arbitrary SQL commands via the start parameter in a search action.

Exploit
  • EPSS 1.25%
  • Published 20.03.2007 10:19:00
  • Last modified 09.04.2025 00:30:58

PHP remote file inclusion vulnerability in includes/not_mem.php in the Add Name module for PHP allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

  • EPSS 0.47%
  • Published 08.02.2007 17:28:00
  • Last modified 09.04.2025 00:30:58

phpBB 2.0.20 does not properly verify user-specified input variables used as limits to SQL queries, which allows remote attackers to obtain sensitive information via a negative LIMIT specification, as demonstrated by the start parameter to memberlist...