Show filters
162 Total Results
Displaying 91-100 of 162
Sort by:
Attacker Value
Unknown
CVE-2006-0437
Disclosure Date: February 06, 2006 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in admin_smilies.php in phpBB 2.0.19 allows remote attackers to inject arbitrary web script or HTML via Javascript events such as "onmouseover" in the (1) smile_url or (2) smile_emotion parameters, which bypasses a check for "<" and ">" characters.
0
Attacker Value
Unknown
CVE-2006-0450
Disclosure Date: January 27, 2006 (last updated February 22, 2025)
phpBB 2.0.19 and earlier allows remote attackers to cause a denial of service (application crash) by (1) registering many users through profile.php or (2) using search.php to search in a certain way that confuses the database.
0
Attacker Value
Unknown
CVE-2006-0063
Disclosure Date: January 05, 2006 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in phpBB 2.0.19, when "Allowed HTML tags" is enabled, allows remote attackers to inject arbitrary web script or HTML via a permitted HTML tag with ' (single quote) characters and active attributes such as onmouseover, a variant of CVE-2005-4357.
0
Attacker Value
Unknown
CVE-2005-3536
Disclosure Date: December 22, 2005 (last updated February 22, 2025)
SQL injection vulnerability in phpBB 2 before 2.0.18 allows remote attackers to execute arbitrary SQL commands via the topic type.
0
Attacker Value
Unknown
CVE-2005-3537
Disclosure Date: December 22, 2005 (last updated February 22, 2025)
A "missing request validation" error in phpBB 2 before 2.0.18 allows remote attackers to edit private messages of other users, probably by modifying certain parameters or other inputs.
0
Attacker Value
Unknown
CVE-2005-4358
Disclosure Date: December 20, 2005 (last updated February 22, 2025)
admin/admin_disallow.php in phpBB 2.0.18 allows remote attackers to obtain the installation path via a direct request with a non-empty setmodules parameter, which causes an invalid append_sid function call that leaks the path in an error message.
0
Attacker Value
Unknown
CVE-2005-4357
Disclosure Date: December 20, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in phpBB 2.0.18, when "Allowed HTML tags" is enabled, allows remote attackers to inject arbitrary Javascript via a permitted HTML tag with " (quote) characters and active attributes such as onmouseover.
0
Attacker Value
Unknown
CVE-2005-4346
Disclosure Date: December 19, 2005 (last updated February 22, 2025)
Invalid SQL syntax error in blog.php in phpBB Blog 2.2.2 and earlier allows remote attackers to obtain the full path of the application via an invalid permalink parameter to index.php, which produces an invalid SQL query that leaks the full pathname in a SQL syntax error message. NOTE: this was originally claimed to be SQL injection, but a cleansing step strips all non-digit characters and leaves an empty permalink argument, which leads to the syntax error.
0
Attacker Value
Unknown
CVE-2005-4083
Disclosure Date: December 08, 2005 (last updated February 22, 2025)
Directory traversal vulnerability in xs_edit.php in the eXtreme Styles phpBB module 2.2.1 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the edit parameter.
0
Attacker Value
Unknown
CVE-2005-4084
Disclosure Date: December 08, 2005 (last updated February 22, 2025)
xs_edit.php in the phpBB eXtreme Styles module 2.2.1 and earlier allows remote attackers to obtain the installation path of the application via an invalid viewbackup parameter.
0