Show filters
39 Total Results
Displaying 31-39 of 39
Sort by:
Attacker Value
Unknown

CVE-2005-2673

Disclosure Date: August 23, 2005 (last updated February 22, 2025)
SQL injection vulnerability in modcp.php in WoltLab Burning Board 2.2.2 and 2.3.3 allows remote authenticated attackers to execute arbitrary SQL commands via the (1) x or (2) y parameters.
0
Attacker Value
Unknown

CVE-2005-1642

Disclosure Date: May 17, 2005 (last updated February 22, 2025)
SQL injection vulnerability in the verify_email function in Woltlab Burning Board 2.x and earlier allows remote attackers to execute arbitrary SQL commands via the $email variable.
0
Attacker Value
Unknown

CVE-2005-1327

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in pms.php for Woltlab Burning Board 2.3.1 PL2 and earlier allows remote attackers to inject arbitrary web script or HTML via the folderid parameter.
0
Attacker Value
Unknown

CVE-2005-0661

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
SQL injection vulnerability in the getwbbuserdata function in session.php for Woltlab Burning Board 2.0.3 through 2.3.0 allows remote attackers to execute arbitrary SQL commands via the (1) userid or (2) lastvisit cookie.
0
Attacker Value
Unknown

CVE-2005-1285

Disclosure Date: April 22, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in thread.php in WoltLab Burning Board 2.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the hilight parameter.
0
Attacker Value
Unknown

CVE-2005-0284

Disclosure Date: January 10, 2005 (last updated February 22, 2025)
SQL injection vulnerability in addentry.php in Woltlab Burning Book 1.0 Gold, 1.1.1e, and possibly other versions, allows remote attackers to execute arbitrary SQL commands via the user-agent parameter.
0
Attacker Value
Unknown

CVE-2002-1505

Disclosure Date: April 02, 2003 (last updated February 22, 2025)
SQL injection vulnerability in board.php for WoltLab Burning Board (wBB) 2.0 RC 1 and earlier allows remote attackers to modify the database and possibly gain privileges via the boardid parameter.
0
Attacker Value
Unknown

CVE-2002-2021

Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in WoltLab Burning Board (wbboard) 1.1.1 allows remote attackers to inject arbitrary web script or HTML via the message parameter.
0
Attacker Value
Unknown

CVE-2002-0903

Disclosure Date: October 04, 2002 (last updated February 22, 2025)
register.php for WoltLab Burning Board (wbboard) 1.1.1 uses a small number of random values for the "code" parameter that is provided to action.php to approve a new registration, along with predictable new user ID's, which allows remote attackers to hijack new user accounts via a brute force attack on the new user ID and the code value.
0