Show filters
183 Total Results
Displaying 91-100 of 183
Sort by:
Attacker Value
Unknown

CVE-2006-5083

Disclosure Date: September 29, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in includes/functions_portal.php in Integrated MODs (IM) Portal 1.2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
0
Attacker Value
Unknown

CVE-2006-4893

Disclosure Date: September 19, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in bb_usage_stats/includes/bb_usage_stats.php in phpBB XS 0.58 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter, a different vector than CVE-2006-4780.
0
Attacker Value
Unknown

CVE-2006-4780

Disclosure Date: September 14, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in includes/functions.php in phpBB XS 0.58 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
0
Attacker Value
Unknown

CVE-2006-4779

Disclosure Date: September 14, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in includes/functions_portal.php in Vitrax Premodded phpBB 1.0.6-R3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
0
Attacker Value
Unknown

CVE-2006-4758

Disclosure Date: September 13, 2006 (last updated October 04, 2023)
phpBB 2.0.21 does not properly handle pathnames ending in %00, which allows remote authenticated administrative users to upload arbitrary files, as demonstrated by a query to admin/admin_board.php with an avatar_path parameter ending in .php%00.
0
Attacker Value
Unknown

CVE-2006-4450

Disclosure Date: August 30, 2006 (last updated October 04, 2023)
usercp_avatar.php in PHPBB 2.0.20, when avatar uploading is enabled, allows remote attackers to use the server as a web proxy by submitting a URL to the avatarurl parameter, which is then used in an HTTP GET request.
0
Attacker Value
Unknown

CVE-2006-3940

Disclosure Date: July 31, 2006 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in phpbb-Auction allow remote attackers to execute arbitrary SQL commands via (1) the ar parameter in auction_room.php and (2) the u parameter in auction_store.php. NOTE: the auction_rating.php vector is already covered by CVE-2005-1234. NOTE: the original disclosure states that the product name is "PHP-Auction", but this is probably an error.
0
Attacker Value
Unknown

CVE-2006-2865

Disclosure Date: June 06, 2006 (last updated November 08, 2023)
PHP remote file inclusion vulnerability in template.php in phpBB 2 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. NOTE: followup posts have disputed this issue, stating that template.php does not appear in phpBB and does not use a $page variable. It is possible that this is a site-specific vulnerability, or an issue in a mod
0
Attacker Value
Unknown

CVE-2006-2736

Disclosure Date: June 01, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in blend_data/blend_common.php in Blend Portal 1.2.0, as used with phpBB when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. NOTE: This is a similar vulnerability to CVE-2006-2507.
0
Attacker Value
Unknown

CVE-2006-2359

Disclosure Date: May 15, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in charts.php in the Chart mod for phpBB allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: this issue might be resultant from SQL injection.
0