Show filters
38 Total Results
Displaying 31-38 of 38
Sort by:
Attacker Value
Unknown

CVE-2004-1950

Disclosure Date: April 19, 2004 (last updated February 22, 2025)
phpBB 2.0.8a and earlier trusts the IP address that is in the X-Forwarded-For in the HTTP header, which allows remote attackers to spoof IP addresses.
0
Attacker Value
Unknown

CVE-2003-1244

Disclosure Date: December 31, 2003 (last updated February 22, 2025)
SQL injection vulnerability in page_header.php in phpBB 2.0, 2.0.1 and 2.0.2 allows remote attackers to brute force user passwords and possibly gain unauthorized access to forums via the forum_id parameter to index.php.
0
Attacker Value
Unknown

CVE-2003-1215

Disclosure Date: December 29, 2003 (last updated February 22, 2025)
SQL injection vulnerability in groupcp.php for phpBB 2.0.6 and earlier allows group moderators to perform unauthorized activities via the sql_in parameter.
0
Attacker Value
Unknown

CVE-2003-1216

Disclosure Date: November 27, 2003 (last updated February 22, 2025)
SQL injection vulnerability in search.php for phpBB 2.0.6 and earlier allows remote attackers to execute arbitrary SQL and gain privileges via the search_id parameter.
0
Attacker Value
Unknown

CVE-2002-1537

Disclosure Date: March 31, 2003 (last updated February 22, 2025)
admin_ug_auth.php in phpBB 2.0.0 allows local users to gain administrator privileges by directly calling admin_ug_auth.php with modifed form fields such as "u".
0
Attacker Value
Unknown

CVE-2002-2176

Disclosure Date: December 31, 2002 (last updated February 22, 2025)
SQL injection vulnerability in Gender MOD 1.1.3 allows remote attackers to gain administrative access via the user_level parameter in the User Profile page.
0
Attacker Value
Unknown

CVE-2002-1707

Disclosure Date: December 31, 2002 (last updated February 22, 2025)
install.php in phpBB 2.0 through 2.0.1, when "allow_url_fopen" and "register_globals" variables are set to "on", allows remote attackers to execute arbitrary PHP code by modifying the phpbb_root_dir parameter to reference a URL on a remote web server that contains the code.
0
Attacker Value
Unknown

CVE-2002-0902

Disclosure Date: October 04, 2002 (last updated February 22, 2025)
Cross-site scripting vulnerability in phpBB 2.0.0 (phpBB2) allows remote attackers to execute Javascript as other phpBB users by including a http:// and a double-quote (") in the [IMG] tag, which bypasses phpBB's security check, terminates the src parameter of the resulting HTML IMG tag, and injects the script.
0