exbb records
4 published records for vendor exbb.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-20 Improper Input Validation1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
31Monitor | CVE-2006-4544No exploit | Multiple PHP remote file inclusion vulnerabilities in ExBB 1.9.1, when register_globals is enabled, allow remote attackers to execute arbitrexbb · exbb | High7.5 | — | 1.8% | Sep 5, 2006 |
28Monitor | CVE-2008-1862Proof of concept | ExBB Italia 0.22 and earlier only checks GET requests that use the QUERY_STRING for certain path manipulations, which allows remote attackerexbb · exbb italia · CWE-20 | Medium6.8 | — | 3.1% | Apr 17, 2008 |
21Monitor | CVE-2006-4488Proof of concept | PHP remote file inclusion vulnerability in modules/userstop/userstop.php in ExBB Italia 0.2 and earlier, when register_globals is enabled, aexbb · exbb italia | Medium5.1 | — | 3.2% | Aug 31, 2006 |
21Monitor | CVE-2008-1861Proof of concept | Directory traversal vulnerability in modules/threadstop/threadstop.php in ExBB Italia 0.22 and earlier, when register_globals is enabled andexbb · exbb italia · CWE-22 | Medium5.1 | — | 1.9% | Apr 17, 2008 |
- CVE-2006-454431Monitor
Multiple PHP remote file inclusion vulnerabilities in ExBB 1.9.1, when register_globals is enabled, allow remote attackers to execute arbitr
HighCVSS 7.5No exploitEPSS 2%exbb · exbbSep 5, 2006
- CVE-2008-186228Monitor
ExBB Italia 0.22 and earlier only checks GET requests that use the QUERY_STRING for certain path manipulations, which allows remote attacker
MediumCVSS 6.8Proof of conceptEPSS 3%exbb · exbb italiaApr 17, 2008
- CVE-2006-448821Monitor
PHP remote file inclusion vulnerability in modules/userstop/userstop.php in ExBB Italia 0.2 and earlier, when register_globals is enabled, a
MediumCVSS 5.1Proof of conceptEPSS 3%exbb · exbb italiaAug 31, 2006
- CVE-2008-186121Monitor
Directory traversal vulnerability in modules/threadstop/threadstop.php in ExBB Italia 0.22 and earlier, when register_globals is enabled and
MediumCVSS 5.1Proof of conceptEPSS 2%exbb · exbb italiaApr 17, 2008