Show filters
79 Total Results
Displaying 1-10 of 79
Sort by:
Attacker Value
Unknown

CVE-2008-7143

Disclosure Date: September 01, 2009 (last updated October 04, 2023)
phpBB 2.0.23 includes the session ID in a request to modcp.php when the moderator or administrator closes a thread, which allows remote attackers to hijack the session via a post in the thread containing a URL to a remotely hosted image, which might include the session ID in the Referer header.
0
Attacker Value
Unknown

CVE-2008-6506

Disclosure Date: March 23, 2009 (last updated October 04, 2023)
Unspecified vulnerability in phpBB before 3.0.4 allows attackers to bypass intended access restrictions and activate de-activated accounts via unknown vectors.
0
Attacker Value
Unknown

CVE-2008-4125

Disclosure Date: September 18, 2008 (last updated October 04, 2023)
The search function in phpBB 2.x provides a search_id value that leaks the state of PHP's PRNG, which allows remote attackers to obtain potentially sensitive information, as demonstrated by a cross-application attack against WordPress, a different vulnerability than CVE-2006-0632.
0
Attacker Value
Unknown

CVE-2008-0471

Disclosure Date: January 29, 2008 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in privmsg.php in phpBB 2.0.22 allows remote attackers to delete private messages (PM) as arbitrary users via a deleteall action.
0
Attacker Value
Unknown

CVE-2007-5033

Disclosure Date: September 21, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in profile.php in phpBB XS 2 allows remote attackers to inject arbitrary web script or HTML via the selfdes parameter in a profile_info editprofile action.
0
Attacker Value
Unknown

CVE-2007-1695

Disclosure Date: March 27, 2007 (last updated November 08, 2023)
PHP remote file inclusion vulnerability in includes/usercp_register.php in phpBB 2.0.19 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. NOTE: this issue has been disputed by third-party researchers, stating that the file checks for a global constant and cannot be accessed directly
0
Attacker Value
Unknown

CVE-2006-7076

Disclosure Date: March 02, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in guestbook.php in Advanced Guestbook 2.4 for phpBB allows remote attackers to inject arbitrary web script or HTML via the entry parameter. NOTE: this issue might be resultant from SQL injection.
0
Attacker Value
Unknown

CVE-2006-7077

Disclosure Date: March 02, 2007 (last updated October 04, 2023)
SQL injection vulnerability in guestbook.php in Advanced Guestbook 2.4 for phpBB allows remote attackers to execute arbitrary SQl commands via the entry parameter.
0
Attacker Value
Unknown

CVE-2006-2219

Disclosure Date: February 08, 2007 (last updated October 04, 2023)
phpBB 2.0.20 does not verify user-specified input variable types before being passed to type-dependent functions, which allows remote attackers to obtain sensitive information, as demonstrated by the (1) mode parameter to memberlist.php and the (2) highlight parameter to viewtopic.php that are used as an argument to the htmlspecialchars or urlencode functions, which displays the installation path in the resulting error message.
0
Attacker Value
Unknown

CVE-2006-2220

Disclosure Date: February 08, 2007 (last updated October 04, 2023)
phpBB 2.0.20 does not properly verify user-specified input variables used as limits to SQL queries, which allows remote attackers to obtain sensitive information via a negative LIMIT specification, as demonstrated by the start parameter to memberlist.php, which reveals the SQL query in the resulting error message.
0