İçeriğe atla
Noroxi

UseBB kayıtları

usebb üreticisine ait 12 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
2
Düzeltme kaydı olan
%0
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Yıllara göre kayıt

  1. 20

Çubuk: toplam · koyu kısım: CISA KEV.

Tekrar eden sınıflar

Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.

CWE

Tüm kayıtlar

12 kayıt
  • CVE-2020-8088
    39İzleyin

    panel_login.php in UseBB 1.0.12 allows type juggling for login bypass because != is used instead of !== for password hashes, which mishandle

    KritikCVSS 9,8İstismar yokEPSS %1

    usebb · usebb27 Oca 2020

  • CVE-2007-3963
    38İzleyin

    Multiple cross-site scripting (XSS) vulnerabilities in UseBB 1.0.7, and possibly other 1.0.x versions, allow remote attackers to inject arbi

    KritikCVSS 9,3Kavram kanıtıEPSS %2

    usebb · usebb25 Tem 2007

  • CVE-2011-3612
    35İzleyin

    Cross-Site Request Forgery (CSRF) vulnerability exists in panel.php in UseBB before 1.0.12.

    YüksekCVSS 8,8İstismar yokEPSS %1

    usebb · usebb22 Oca 2020

  • CVE-2005-2439
    30İzleyin

    SQL injection vulnerability in UseBB 0.5.1 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL

    YüksekCVSS 7,5İstismar yokEPSS %1

    usebb · usebb3 Ağu 2005

  • CVE-2011-3611
    29İzleyin

    A File Inclusion vulnerability exists in act parameter to admin.php in UseBB before 1.0.12.

    YüksekCVSS 7,2İstismar yokEPSS %3

    usebb · usebb22 Oca 2020

  • CVE-2006-2524
    27İzleyin

    Cross-site scripting (XSS) vulnerability in UseBB 1.0 RC1 and earlier allows remote attackers to inject arbitrary web script or HTML via uns

    OrtaCVSS 6,8İstismar yokEPSS %1

    usebb · usebb22 May 2006

  • CVE-2006-2525
    25İzleyin

    SQL injection vulnerability in UseBB 1.0 RC1 and earlier allows remote attackers to execute arbitrary SQL commands via the member list searc

    OrtaCVSS 6,4İstismar yokEPSS %1

    usebb · usebb22 May 2006

  • CVE-2009-4041
    21İzleyin

    UseBB 1.0.9 before 1.0.10 allows remote attackers to cause a denial of service (infinite loop) via crafted BBCode tags.

    OrtaCVSS 5,0İstismar yokEPSS %2

    usebb · usebb20 Kas 2009

  • CVE-2007-2066
    20İzleyin

    UseBB before 1.0.6 allows remote attackers to obtain sensitive information via a request with unspecified GET or POST parameters to an unspe

    OrtaCVSS 5,0İstismar yokEPSS %1

    usebb · usebb17 Nis 2007

  • CVE-2005-2438
    17İzleyin

    Cross-site scripting (XSS) vulnerability in UseBB 0.5.1 and earlier allows remote attackers to inject arbitrary Javascript via the BBCode co

    OrtaCVSS 4,3İstismar yokEPSS %1

    usebb · usebb3 Ağu 2005

  • CVE-2005-4193
    17İzleyin

    Cross-site scripting (XSS) vulnerability in UseBB before 0.7 allows remote attackers to inject arbitrary web script or HTML via the $_SERVER

    OrtaCVSS 4,3İstismar yokEPSS %1

    usebb · usebb13 Ara 2005

  • CVE-2010-3713
    17İzleyin

    rss.php in UseBB before 1.0.11 does not properly handle forum configurations in which a user has the view permission but not the read permis

    OrtaCVSS 4,3İstismar yokEPSS %1

    usebb · usebb27 Eki 2010