Show filters
162 Total Results
Displaying 91-100 of 162
Sort by:
Attacker Value
Unknown

CVE-2006-0437

Disclosure Date: February 06, 2006 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in admin_smilies.php in phpBB 2.0.19 allows remote attackers to inject arbitrary web script or HTML via Javascript events such as "onmouseover" in the (1) smile_url or (2) smile_emotion parameters, which bypasses a check for "<" and ">" characters.
0
Attacker Value
Unknown

CVE-2006-0450

Disclosure Date: January 27, 2006 (last updated February 22, 2025)
phpBB 2.0.19 and earlier allows remote attackers to cause a denial of service (application crash) by (1) registering many users through profile.php or (2) using search.php to search in a certain way that confuses the database.
0
Attacker Value
Unknown

CVE-2006-0063

Disclosure Date: January 05, 2006 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in phpBB 2.0.19, when "Allowed HTML tags" is enabled, allows remote attackers to inject arbitrary web script or HTML via a permitted HTML tag with ' (single quote) characters and active attributes such as onmouseover, a variant of CVE-2005-4357.
0
Attacker Value
Unknown

CVE-2005-3536

Disclosure Date: December 22, 2005 (last updated February 22, 2025)
SQL injection vulnerability in phpBB 2 before 2.0.18 allows remote attackers to execute arbitrary SQL commands via the topic type.
0
Attacker Value
Unknown

CVE-2005-3537

Disclosure Date: December 22, 2005 (last updated February 22, 2025)
A "missing request validation" error in phpBB 2 before 2.0.18 allows remote attackers to edit private messages of other users, probably by modifying certain parameters or other inputs.
0
Attacker Value
Unknown

CVE-2005-4358

Disclosure Date: December 20, 2005 (last updated February 22, 2025)
admin/admin_disallow.php in phpBB 2.0.18 allows remote attackers to obtain the installation path via a direct request with a non-empty setmodules parameter, which causes an invalid append_sid function call that leaks the path in an error message.
0
Attacker Value
Unknown

CVE-2005-4357

Disclosure Date: December 20, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in phpBB 2.0.18, when "Allowed HTML tags" is enabled, allows remote attackers to inject arbitrary Javascript via a permitted HTML tag with " (quote) characters and active attributes such as onmouseover.
0
Attacker Value
Unknown

CVE-2005-4346

Disclosure Date: December 19, 2005 (last updated February 22, 2025)
Invalid SQL syntax error in blog.php in phpBB Blog 2.2.2 and earlier allows remote attackers to obtain the full path of the application via an invalid permalink parameter to index.php, which produces an invalid SQL query that leaks the full pathname in a SQL syntax error message. NOTE: this was originally claimed to be SQL injection, but a cleansing step strips all non-digit characters and leaves an empty permalink argument, which leads to the syntax error.
0
Attacker Value
Unknown

CVE-2005-4083

Disclosure Date: December 08, 2005 (last updated February 22, 2025)
Directory traversal vulnerability in xs_edit.php in the eXtreme Styles phpBB module 2.2.1 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the edit parameter.
0
Attacker Value
Unknown

CVE-2005-4084

Disclosure Date: December 08, 2005 (last updated February 22, 2025)
xs_edit.php in the phpBB eXtreme Styles module 2.2.1 and earlier allows remote attackers to obtain the installation path of the application via an invalid viewbackup parameter.
0