Show filters
183 Total Results
Displaying 101-110 of 183
Sort by:
Attacker Value
Unknown

CVE-2006-2360

Disclosure Date: May 15, 2006 (last updated October 04, 2023)
SQL injection vulnerability in charts.php in the Chart mod for phpBB allows remote attackers to execute arbitrary SQL commands via the id parameter.
0
Attacker Value
Unknown

CVE-2006-2245

Disclosure Date: May 09, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in auction\auction_common.php in Auction mod 1.3m for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
0
Attacker Value
Unknown

CVE-2006-2152

Disclosure Date: May 03, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in admin/addentry.php in phpBB Advanced Guestbook 2.4.0 and earlier, when register_globals is enabled, allows remote attackers to include arbitrary files via the phpbb_root_path parameter.
0
Attacker Value
Unknown

CVE-2006-2151

Disclosure Date: May 03, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in toplist.php in phpBB TopList 1.3.8 and earlier, when register_globals is enabled, allows remote attackers to include arbitrary files via the phpbb_root_path parameter.
0
Attacker Value
Unknown

CVE-2006-2150

Disclosure Date: May 03, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in top/list.php in phpBB TopList 1.3.8 and earlier allows remote attackers to include arbitrary files via the returnpath parameter.
0
Attacker Value
Unknown

CVE-2006-2134

Disclosure Date: May 02, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in /includes/kb_constants.php in Knowledge Base Mod for PHPbb 2.0.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.
0
Attacker Value
Unknown

CVE-2006-1896

Disclosure Date: April 20, 2006 (last updated October 04, 2023)
Unspecified vulnerability in phpBB allows remote authenticated users with Administration Panel access to execute arbitrary PHP code via crafted Font Colour 3 ($theme[fontcolor3] variable) and/or signature values, possibly involving the highlight functionality. NOTE: the original report does not clarify whether this issue is static code injection, eval injection, or another type of vulnerability.
0
Attacker Value
Unknown

CVE-2006-1895

Disclosure Date: April 20, 2006 (last updated October 04, 2023)
Direct static code injection vulnerability in includes/template.php in phpBB allows remote authenticated users with write access to execute arbitrary PHP code by modifying a template in a way that (1) bypasses a loose ".*" regular expression to match BEGIN and END statements in overall_header.tpl, or (2) is used in an eval statement by includes/bbcode.php for bbcode.tpl.
0
Attacker Value
Unknown

CVE-2006-1775

Disclosure Date: April 13, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in phpBB 2.0.19 allow remote attackers to inject arbitrary web script or HTML via the (1) Site Description field in (a) admin_board.php, the (2) Group name and (3) Group description fields in (b) admin_groups.php and (c) groupcp.php, the (4) Theme Name field in (d) admin_styles.php, and the (5) Rank Title field in (e) admin_ranks.php. NOTE: the profile.php/Current password vector is already covered by CVE-2006-1603.
0
Attacker Value
Unknown

CVE-2006-1603

Disclosure Date: April 04, 2006 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in profile.php in phpBB 2.0.19 allows remote attackers to inject arbitrary web script or HTML via the cur_password parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0