Show filters
39 Total Results
Displaying 11-20 of 39
Sort by:
Attacker Value
Unknown

CVE-2007-0388

Disclosure Date: January 19, 2007 (last updated October 04, 2023)
SQL injection vulnerability in search.php in Woltlab Burning Board (wBB) 1.0.2 and earlier, and 2.3.6 and earlier in the 2.x series, allows remote attackers to execute arbitrary SQL commands via the boardids[1] and other boardids[] parameters.
0
Attacker Value
Unknown

CVE-2006-6289

Disclosure Date: December 05, 2006 (last updated October 04, 2023)
Woltlab Burning Board (wBB) Lite 1.0.2 does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to execute arbitrary SQL commands via the wbb_userid parameter to the top-level URI. NOTE: it could be argued that this vulnerability is due to a bug in the unset PHP command (CVE-2006-3017) and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in wBB Lite.
0
Attacker Value
Unknown

CVE-2006-6237

Disclosure Date: December 03, 2006 (last updated October 04, 2023)
SQL injection vulnerability in the decode_cookie function in thread.php in Woltlab Burning Board Lite 1.0.2 allows remote attackers to execute arbitrary SQL commands via the threadvisit Cookie parameter.
0
Attacker Value
Unknown

CVE-2006-5508

Disclosure Date: October 25, 2006 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in addentry.php in WoltLab Burning Book 1.1.2 allow remote attackers to execute arbitrary SQL commands via (1) the n parameter and (2) the User-Agent HTTP header.
0
Attacker Value
Unknown

CVE-2006-5509

Disclosure Date: October 25, 2006 (last updated October 04, 2023)
Eval injection vulnerability in addentry.php in WoltLab Burning Book 1.1.2 allows remote attackers to execute arbitrary PHP code via crafted POST requests that store PHP code in a database that is later processed by eval, as demonstrated using SQL injection via the n parameter.
0
Attacker Value
Unknown

CVE-2006-5029

Disclosure Date: September 27, 2006 (last updated October 04, 2023)
SQL injection vulnerability in thread.php in WoltLab Burning Board (wBB) 2.3.x allows remote attackers to obtain the version numbers of PHP, MySQL, and wBB via the page parameter. NOTE: this issue might be a forced SQL error. Also, the original report was disputed by a third party for 2.3.3 and 2.3.4.
0
Attacker Value
Unknown

CVE-2006-4317

Disclosure Date: August 24, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in attachment.php in WoltLab Burning Board (WBB) 2.3.5 allows remote attackers to inject arbitrary web script or HTML via a GIF image that contains URL-encoded Javascript.
0
Attacker Value
Unknown

CVE-2006-3256

Disclosure Date: June 28, 2006 (last updated October 04, 2023)
SQL injection vulnerability in report.php in Woltlab Burning Board (WBB) 2.3.1 allows remote attackers to execute arbitrary SQL commands via the postid parameter.
0
Attacker Value
Unknown

CVE-2006-3255

Disclosure Date: June 28, 2006 (last updated October 04, 2023)
SQL injection vulnerability in showmods.php in Woltlab Burning Board (WBB) 1.2 allows remote attackers to execute arbitrary SQL commands via the boardid parameter.
0
Attacker Value
Unknown

CVE-2006-3254

Disclosure Date: June 28, 2006 (last updated October 04, 2023)
SQL injection vulnerability in newthread.php in Woltlab Burning Board (WBB) 2.0 RC2 allows remote attackers to execute arbitrary SQL commands via the boardid parameter.
0