Show filters
183 Total Results
Displaying 111-120 of 183
Sort by:
Attacker Value
Unknown

CVE-2006-0632

Disclosure Date: February 10, 2006 (last updated February 22, 2025)
The gen_rand_string function in phpBB 2.0.19 uses insufficiently random data (small value space) to create the activation key ("validation ID") that is sent by e-mail when establishing a password, which makes it easier for remote attackers to obtain the key and modify passwords for existing accounts or create new accounts.
0
Attacker Value
Unknown

CVE-2006-0438

Disclosure Date: February 06, 2006 (last updated February 22, 2025)
Cross-site request forgery (CSRF) vulnerability in phpBB 2.0.19, when Link to off-site Avatar or bbcode (IMG) are enabled, allows remote attackers to perform unauthorized actions as a logged in user via a link or IMG tag in a user profile, as demonstrated using links to (1) admin/admin_users.php and (2) modcp.php.
0
Attacker Value
Unknown

CVE-2006-0437

Disclosure Date: February 06, 2006 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in admin_smilies.php in phpBB 2.0.19 allows remote attackers to inject arbitrary web script or HTML via Javascript events such as "onmouseover" in the (1) smile_url or (2) smile_emotion parameters, which bypasses a check for "<" and ">" characters.
0
Attacker Value
Unknown

CVE-2006-0450

Disclosure Date: January 27, 2006 (last updated February 22, 2025)
phpBB 2.0.19 and earlier allows remote attackers to cause a denial of service (application crash) by (1) registering many users through profile.php or (2) using search.php to search in a certain way that confuses the database.
0
Attacker Value
Unknown

CVE-2006-0063

Disclosure Date: January 05, 2006 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in phpBB 2.0.19, when "Allowed HTML tags" is enabled, allows remote attackers to inject arbitrary web script or HTML via a permitted HTML tag with ' (single quote) characters and active attributes such as onmouseover, a variant of CVE-2005-4357.
0
Attacker Value
Unknown

CVE-2005-3536

Disclosure Date: December 22, 2005 (last updated February 22, 2025)
SQL injection vulnerability in phpBB 2 before 2.0.18 allows remote attackers to execute arbitrary SQL commands via the topic type.
0
Attacker Value
Unknown

CVE-2005-3537

Disclosure Date: December 22, 2005 (last updated February 22, 2025)
A "missing request validation" error in phpBB 2 before 2.0.18 allows remote attackers to edit private messages of other users, probably by modifying certain parameters or other inputs.
0
Attacker Value
Unknown

CVE-2005-4358

Disclosure Date: December 20, 2005 (last updated February 22, 2025)
admin/admin_disallow.php in phpBB 2.0.18 allows remote attackers to obtain the installation path via a direct request with a non-empty setmodules parameter, which causes an invalid append_sid function call that leaks the path in an error message.
0
Attacker Value
Unknown

CVE-2005-4357

Disclosure Date: December 20, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in phpBB 2.0.18, when "Allowed HTML tags" is enabled, allows remote attackers to inject arbitrary Javascript via a permitted HTML tag with " (quote) characters and active attributes such as onmouseover.
0
Attacker Value
Unknown

CVE-2005-4083

Disclosure Date: December 08, 2005 (last updated February 22, 2025)
Directory traversal vulnerability in xs_edit.php in the eXtreme Styles phpBB module 2.2.1 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the edit parameter.
0