Show filters
38 Total Results
Displaying 31-38 of 38
Sort by:
Attacker Value
Unknown
CVE-2004-1950
Disclosure Date: April 19, 2004 (last updated February 22, 2025)
phpBB 2.0.8a and earlier trusts the IP address that is in the X-Forwarded-For in the HTTP header, which allows remote attackers to spoof IP addresses.
0
Attacker Value
Unknown
CVE-2003-1244
Disclosure Date: December 31, 2003 (last updated February 22, 2025)
SQL injection vulnerability in page_header.php in phpBB 2.0, 2.0.1 and 2.0.2 allows remote attackers to brute force user passwords and possibly gain unauthorized access to forums via the forum_id parameter to index.php.
0
Attacker Value
Unknown
CVE-2003-1215
Disclosure Date: December 29, 2003 (last updated February 22, 2025)
SQL injection vulnerability in groupcp.php for phpBB 2.0.6 and earlier allows group moderators to perform unauthorized activities via the sql_in parameter.
0
Attacker Value
Unknown
CVE-2003-1216
Disclosure Date: November 27, 2003 (last updated February 22, 2025)
SQL injection vulnerability in search.php for phpBB 2.0.6 and earlier allows remote attackers to execute arbitrary SQL and gain privileges via the search_id parameter.
0
Attacker Value
Unknown
CVE-2002-1537
Disclosure Date: March 31, 2003 (last updated February 22, 2025)
admin_ug_auth.php in phpBB 2.0.0 allows local users to gain administrator privileges by directly calling admin_ug_auth.php with modifed form fields such as "u".
0
Attacker Value
Unknown
CVE-2002-2176
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
SQL injection vulnerability in Gender MOD 1.1.3 allows remote attackers to gain administrative access via the user_level parameter in the User Profile page.
0
Attacker Value
Unknown
CVE-2002-1707
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
install.php in phpBB 2.0 through 2.0.1, when "allow_url_fopen" and "register_globals" variables are set to "on", allows remote attackers to execute arbitrary PHP code by modifying the phpbb_root_dir parameter to reference a URL on a remote web server that contains the code.
0
Attacker Value
Unknown
CVE-2002-0902
Disclosure Date: October 04, 2002 (last updated February 22, 2025)
Cross-site scripting vulnerability in phpBB 2.0.0 (phpBB2) allows remote attackers to execute Javascript as other phpBB users by including a http:// and a double-quote (") in the [IMG] tag, which bypasses phpBB's security check, terminates the src parameter of the resulting HTML IMG tag, and injects the script.
0