phpbb group kayıtları
phpbb group üreticisine ait 93 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 2 · %2,2
- Pre-auth RCE
- 28
- Düzeltme kaydı olan
- %17,2
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tekrar eden sınıflar
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-20 Improper Input Validation1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
93 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
56Planlayın | CVE-2005-2086Silahlaştırılmış | PHP remote file inclusion vulnerability in viewtopic.php in phpBB 2.0.15 and earlier allows remote attackers to execute arbitrary PHP code.phpbb group · phpbb | Yüksek7,5 | — | %85,4 | 5 Tem 2005 |
52Planlayın | CVE-2004-1315Silahlaştırılmış | viewtopic.php in phpBB 2.x before 2.0.11 improperly URL decodes the highlight parameter when extracting words and phrases to highlight, whicphpbb group · phpbb | Yüksek7,5 | — | %72,1 | 12 Kas 2004 |
42Planlayın | CVE-2002-0473İstismar yok | db.php in phpBB 2.0 (aka phpBB2) RC-3 and earlier allows remote attackers to execute arbitrary code from remote servers via the phpbb_root_pphpbb group · phpbb | Kritik10,0 | — | %5,3 | 12 Ağu 2002 |
41Planlayın | CVE-2002-2176Kavram kanıtı | SQL injection vulnerability in Gender MOD 1.1.3 allows remote attackers to gain administrative access via the user_level parameter in the Usphpbb group · phpbb | Kritik10,0 | — | %3,3 | 31 Ara 2002 |
41Planlayın | CVE-2002-1537İstismar yok | admin_ug_auth.php in phpBB 2.0.0 allows local users to gain administrator privileges by directly calling admin_ug_auth.php with modifed formphpbb group · phpbb | Kritik10,0 | — | %2,5 | 31 Mar 2003 |
41Planlayın | CVE-2007-1695İstismar yok | PHP remote file inclusion vulnerability in includes/usercp_register.php in phpBB 2.0.19 allows remote attackers to execute arbitrary PHP codphpbb group · phpbb | Kritik10,0 | — | %1,9 | 26 Mar 2007 |
40Planlayın | CVE-2006-6840İstismar yok | Unspecified vulnerability in phpBB before 2.0.22 has unknown impact and remote attack vectors related to a "negative start parameter."phpbb group · phpbb | Kritik10,0 | — | %1,6 | 31 Ara 2006 |
40Planlayın | CVE-2006-6839İstismar yok | Unspecified vulnerability in phpBB before 2.0.22 has unknown impact and remote attack vectors related to "criteria for 'bad' redirection tarphpbb group · phpbb | Kritik10,0 | — | %1,6 | 31 Ara 2006 |
40Planlayın | CVE-2006-6841İstismar yok | Certain forms in phpBB before 2.0.22 lack session checks, which has unknown impact and remote attack vectors.phpbb group · phpbb | Kritik10,0 | — | %1,6 | 31 Ara 2006 |
35İzleyin | CVE-2005-1193Kavram kanıtı | The bbencode_second_pass and make_clickable functions in bbcode.php for phpBB before 2.0.15, as used in viewtopic.php, privmsg.php, and othephpbb group · phpbb | Yüksek7,5 | — | %16,4 | 16 May 2005 |
33İzleyin | CVE-2006-2151Kavram kanıtı | PHP remote file inclusion vulnerability in toplist.php in phpBB TopList 1.3.8 and earlier, when register_globals is enabled, allows remote aphpbb group · phpbb toplist | Yüksek7,5 | — | %11,0 | 3 May 2006 |
33İzleyin | CVE-2006-2152Kavram kanıtı | PHP remote file inclusion vulnerability in admin/addentry.php in phpBB Advanced Guestbook 2.4.0 and earlier, when register_globals is enablephpbb group · phpbb advanced guestbook | Yüksek7,5 | — | %8,3 | 3 May 2006 |
32İzleyin | CVE-2005-0614Kavram kanıtı | sessions.php in phpBB 2.0.12 and earlier allows remote attackers to gain administrator privileges via the autologinid value in a cookie.phpbb group · phpbb | Yüksek7,5 | — | %7,6 | 2 May 2005 |
32İzleyin | CVE-2002-0902Kavram kanıtı | Cross-site scripting vulnerability in phpBB 2.0.0 (phpBB2) allows remote attackers to execute Javascript as other phpBB users by including aphpbb group · phpbb | Yüksek7,5 | — | %7,2 | 4 Eki 2002 |
32İzleyin | CVE-2004-1535Kavram kanıtı | PHP remote file inclusion vulnerability in admin_cash.php for the Cash Mod module for phpBB allows remote attackers to execute arbitrary PHPphpbb group · phpbb | Yüksek7,5 | — | %6,3 | 31 Ara 2004 |
31İzleyin | CVE-2006-4779Kavram kanıtı | PHP remote file inclusion vulnerability in includes/functions_portal.php in Vitrax Premodded phpBB 1.0.6-R3 and earlier allows remote attackphpbb group · vitrax premodded phpbb | Yüksek7,5 | — | %2,9 | 14 Eyl 2006 |
31İzleyin | CVE-2006-2865Kavram kanıtı | PHP remote file inclusion vulnerability in template.php in phpBB 2 allows remote attackers to execute arbitrary PHP code via a URL in the paphpbb group · phpbb | Yüksek7,5 | — | %2,8 | 6 Haz 2006 |
31İzleyin | CVE-2004-1943Kavram kanıtı | PHP remote file inclusion vulnerability in album_portal.php in phpBB modified by Przemo 1.8 allows remote attackers to execute arbitrary PHPphpbb group · phpbb | Yüksek7,5 | — | %2,6 | 19 Nis 2004 |
31İzleyin | CVE-2005-3415İstismar yok | phpBB 2.0.17 and earlier allows remote attackers to bypass protection mechanisms that deregister global variables by setting both a GET/POSTphpbb group · phpbb | Yüksek7,5 | — | %2,4 | 1 Kas 2005 |
31İzleyin | CVE-2005-3420İstismar yok | usercp_register.php in phpBB 2.0.17 allows remote attackers to modify regular expressions and execute PHP code via the signature_bbcode_uid phpbb group · phpbb | Yüksek7,5 | — | %2,4 | 1 Kas 2005 |
31İzleyin | CVE-2005-3417İstismar yok | phpBB 2.0.17 and earlier, when the register_long_arrays directive is disabled, allows remote attackers to modify global variables and bypassphpbb group · phpbb | Yüksek7,5 | — | %2,3 | 1 Kas 2005 |
31İzleyin | CVE-2005-3416İstismar yok | phpBB 2.0.17 and earlier, when register_globals is enabled and the session_start function has not been called to handle a session, allows rephpbb group · phpbb | Yüksek7,5 | — | %2,3 | 1 Kas 2005 |
31İzleyin | CVE-2006-5209Kavram kanıtı | PHP remote file inclusion vulnerability in admin/admin_topic_action_logging.php in Admin Topic Action Logging Mod 0.95 and earlier, as used phpbb group · phpbb | Yüksek7,5 | — | %2,3 | 10 Eki 2006 |
31İzleyin | CVE-2005-1047İstismar yok | Meilad File upload script (up.php) mod for phpBB 2.0.x does not properly limit the types of files that can be uploaded, which allows remote phpbb group · phpbb | Yüksek7,5 | — | %2,1 | 7 Nis 2005 |
31İzleyin | CVE-2005-1196Kavram kanıtı | SQL injection vulnerability in kb.php in the Knowledge Base module for phpBB allows remote attackers to obtain sensitive information and exephpbb group · phpbb | Yüksek7,5 | — | %2,0 | 2 May 2005 |
- CVE-2005-208656Planlayın
PHP remote file inclusion vulnerability in viewtopic.php in phpBB 2.0.15 and earlier allows remote attackers to execute arbitrary PHP code.
YüksekCVSS 7,5SilahlaştırılmışEPSS %85phpbb group · phpbb5 Tem 2005
- CVE-2004-131552Planlayın
viewtopic.php in phpBB 2.x before 2.0.11 improperly URL decodes the highlight parameter when extracting words and phrases to highlight, whic
YüksekCVSS 7,5SilahlaştırılmışEPSS %72phpbb group · phpbb12 Kas 2004
- CVE-2002-047342Planlayın
db.php in phpBB 2.0 (aka phpBB2) RC-3 and earlier allows remote attackers to execute arbitrary code from remote servers via the phpbb_root_p
KritikCVSS 10,0İstismar yokEPSS %5phpbb group · phpbb12 Ağu 2002
- CVE-2002-217641Planlayın
SQL injection vulnerability in Gender MOD 1.1.3 allows remote attackers to gain administrative access via the user_level parameter in the Us
KritikCVSS 10,0Kavram kanıtıEPSS %3phpbb group · phpbb31 Ara 2002
- CVE-2002-153741Planlayın
admin_ug_auth.php in phpBB 2.0.0 allows local users to gain administrator privileges by directly calling admin_ug_auth.php with modifed form
KritikCVSS 10,0İstismar yokEPSS %2phpbb group · phpbb31 Mar 2003
- CVE-2007-169541Planlayın
PHP remote file inclusion vulnerability in includes/usercp_register.php in phpBB 2.0.19 allows remote attackers to execute arbitrary PHP cod
KritikCVSS 10,0İstismar yokEPSS %2phpbb group · phpbb26 Mar 2007
- CVE-2006-684040Planlayın
Unspecified vulnerability in phpBB before 2.0.22 has unknown impact and remote attack vectors related to a "negative start parameter."
KritikCVSS 10,0İstismar yokEPSS %2phpbb group · phpbb31 Ara 2006
- CVE-2006-683940Planlayın
Unspecified vulnerability in phpBB before 2.0.22 has unknown impact and remote attack vectors related to "criteria for 'bad' redirection tar
KritikCVSS 10,0İstismar yokEPSS %2phpbb group · phpbb31 Ara 2006
- CVE-2006-684140Planlayın
Certain forms in phpBB before 2.0.22 lack session checks, which has unknown impact and remote attack vectors.
KritikCVSS 10,0İstismar yokEPSS %2phpbb group · phpbb31 Ara 2006
- CVE-2005-119335İzleyin
The bbencode_second_pass and make_clickable functions in bbcode.php for phpBB before 2.0.15, as used in viewtopic.php, privmsg.php, and othe
YüksekCVSS 7,5Kavram kanıtıEPSS %16phpbb group · phpbb16 May 2005
- CVE-2006-215133İzleyin
PHP remote file inclusion vulnerability in toplist.php in phpBB TopList 1.3.8 and earlier, when register_globals is enabled, allows remote a
YüksekCVSS 7,5Kavram kanıtıEPSS %11phpbb group · phpbb toplist3 May 2006
- CVE-2006-215233İzleyin
PHP remote file inclusion vulnerability in admin/addentry.php in phpBB Advanced Guestbook 2.4.0 and earlier, when register_globals is enable
YüksekCVSS 7,5Kavram kanıtıEPSS %8phpbb group · phpbb advanced guestbook3 May 2006
- CVE-2005-061432İzleyin
sessions.php in phpBB 2.0.12 and earlier allows remote attackers to gain administrator privileges via the autologinid value in a cookie.
YüksekCVSS 7,5Kavram kanıtıEPSS %8phpbb group · phpbb2 May 2005
- CVE-2002-090232İzleyin
Cross-site scripting vulnerability in phpBB 2.0.0 (phpBB2) allows remote attackers to execute Javascript as other phpBB users by including a
YüksekCVSS 7,5Kavram kanıtıEPSS %7phpbb group · phpbb4 Eki 2002
- CVE-2004-153532İzleyin
PHP remote file inclusion vulnerability in admin_cash.php for the Cash Mod module for phpBB allows remote attackers to execute arbitrary PHP
YüksekCVSS 7,5Kavram kanıtıEPSS %6phpbb group · phpbb31 Ara 2004
- CVE-2006-477931İzleyin
PHP remote file inclusion vulnerability in includes/functions_portal.php in Vitrax Premodded phpBB 1.0.6-R3 and earlier allows remote attack
YüksekCVSS 7,5Kavram kanıtıEPSS %3phpbb group · vitrax premodded phpbb14 Eyl 2006
- CVE-2006-286531İzleyin
PHP remote file inclusion vulnerability in template.php in phpBB 2 allows remote attackers to execute arbitrary PHP code via a URL in the pa
YüksekCVSS 7,5Kavram kanıtıEPSS %3phpbb group · phpbb6 Haz 2006
- CVE-2004-194331İzleyin
PHP remote file inclusion vulnerability in album_portal.php in phpBB modified by Przemo 1.8 allows remote attackers to execute arbitrary PHP
YüksekCVSS 7,5Kavram kanıtıEPSS %3phpbb group · phpbb19 Nis 2004
- CVE-2005-341531İzleyin
phpBB 2.0.17 and earlier allows remote attackers to bypass protection mechanisms that deregister global variables by setting both a GET/POST
YüksekCVSS 7,5İstismar yokEPSS %2phpbb group · phpbb1 Kas 2005
- CVE-2005-342031İzleyin
usercp_register.php in phpBB 2.0.17 allows remote attackers to modify regular expressions and execute PHP code via the signature_bbcode_uid
YüksekCVSS 7,5İstismar yokEPSS %2phpbb group · phpbb1 Kas 2005
- CVE-2005-341731İzleyin
phpBB 2.0.17 and earlier, when the register_long_arrays directive is disabled, allows remote attackers to modify global variables and bypass
YüksekCVSS 7,5İstismar yokEPSS %2phpbb group · phpbb1 Kas 2005
- CVE-2005-341631İzleyin
phpBB 2.0.17 and earlier, when register_globals is enabled and the session_start function has not been called to handle a session, allows re
YüksekCVSS 7,5İstismar yokEPSS %2phpbb group · phpbb1 Kas 2005
- CVE-2006-520931İzleyin
PHP remote file inclusion vulnerability in admin/admin_topic_action_logging.php in Admin Topic Action Logging Mod 0.95 and earlier, as used
YüksekCVSS 7,5Kavram kanıtıEPSS %2phpbb group · phpbb10 Eki 2006
- CVE-2005-104731İzleyin
Meilad File upload script (up.php) mod for phpBB 2.0.x does not properly limit the types of files that can be uploaded, which allows remote
YüksekCVSS 7,5İstismar yokEPSS %2phpbb group · phpbb7 Nis 2005
- CVE-2005-119631İzleyin
SQL injection vulnerability in kb.php in the Knowledge Base module for phpBB allows remote attackers to obtain sensitive information and exe
YüksekCVSS 7,5Kavram kanıtıEPSS %2phpbb group · phpbb2 May 2005