openbb records
12 published records for vendor openbb.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 7
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Attack profile
All records
12 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2004-1967No exploit | Cross-site request forgery (CSRF) vulnerabilities in (1) cp_forums.php, (2) cp_usergroup.php, (3) cp_ipbans.php, (4) myhome.php, (5) post.phopenbb · openbb · CWE-352 | High8.8 | — | 1.6% | Apr 25, 2004 |
32Monitor | CVE-2002-0330Proof of concept | Cross-site scripting vulnerability in codeparse.php of Open Bulletin Board (OpenBB) 1.0.0 allows remote attackers to execute arbitrary scripopenbb · openbb | High7.5 | — | 7.9% | Jun 25, 2002 |
31Monitor | CVE-2006-4722Proof of concept | PHP remote file inclusion vulnerability in Open Bulletin Board (OpenBB) 1.0.8 and earlier allows remote attackers to execute arbitrary PHP copenbb · openbb | High7.5 | — | 2.8% | Sep 12, 2006 |
31Monitor | CVE-2005-1612Proof of concept | SQL injection vulnerability in read.php in Open Bulletin Board (OpenBB) 1.0.8 allows remote attackers to execute arbitrary SQL commands via openbb · openbb | High7.5 | — | 2.2% | May 16, 2005 |
30Monitor | CVE-2004-1969No exploit | The avatar upload capability in Open Bulletin Board (OpenBB) 1.0.6 and earlier allows remote attackers to execute arbitrary script by uploadopenbb · openbb | High7.5 | — | 1.5% | Apr 25, 2004 |
30Monitor | CVE-2004-1966Proof of concept | Multiple SQL injection vulnerabilities in Open Bulletin Board (OpenBB) 1.0.6 and earlier allow remote attackers to execute arbitrary SQL comopenbb · openbb | High7.5 | — | 1.3% | Dec 31, 2004 |
30Monitor | CVE-2005-2566No exploit | Multiple SQL injection vulnerabilities in Open Bulletin Board (OpenBB) allow remote attackers to execute arbitrary SQL commands via the (1) openbb · openbb | High7.5 | — | 1.1% | Aug 16, 2005 |
28Monitor | CVE-2005-1613Proof of concept | Cross-site scripting (XSS) vulnerability in member.php in Open Bulletin Board (OpenBB) 1.0.8 allows remote attackers to inject arbitrary webopenbb · openbb | Medium6.8 | — | 3.7% | May 16, 2005 |
22Monitor | CVE-2002-1830Proof of concept | Open Bulletin Board (OpenBB) 1.0.0 RC3 allows remote attackers to bypass authentication and access modifier options via a direct request to openbb · openbb | Medium5.0 | — | 7.1% | Dec 31, 2002 |
21Monitor | CVE-2004-1968Proof of concept | The readmsg action in myhome.php in Open Bulletin Board (OpenBB) 1.0.6 and earlier allows remote attackers to read arbitrary messages by modopenbb · openbb | Medium5.0 | — | 2.9% | Apr 26, 2004 |
20Monitor | CVE-2004-1965Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in Open Bulletin Board (OpenBB) 1.0.6 and earlier allows remote attackers to inject arbiopenbb · openbb | Medium4.3 | — | 9.0% | Apr 25, 2004 |
18Monitor | CVE-2002-1829Proof of concept | Cross-site scripting (XSS) vulnerability in codeparse.php in Open Bulletin Board (OpenBB) 1.0.0 RC3 allows remote attackers to inject arbitropenbb · openbb | Medium4.3 | — | 3.6% | Dec 31, 2002 |
- CVE-2004-196735Monitor
Cross-site request forgery (CSRF) vulnerabilities in (1) cp_forums.php, (2) cp_usergroup.php, (3) cp_ipbans.php, (4) myhome.php, (5) post.ph
HighCVSS 8.8No exploitEPSS 2%openbb · openbbApr 25, 2004
- CVE-2002-033032Monitor
Cross-site scripting vulnerability in codeparse.php of Open Bulletin Board (OpenBB) 1.0.0 allows remote attackers to execute arbitrary scrip
HighCVSS 7.5Proof of conceptEPSS 8%openbb · openbbJun 25, 2002
- CVE-2006-472231Monitor
PHP remote file inclusion vulnerability in Open Bulletin Board (OpenBB) 1.0.8 and earlier allows remote attackers to execute arbitrary PHP c
HighCVSS 7.5Proof of conceptEPSS 3%openbb · openbbSep 12, 2006
- CVE-2005-161231Monitor
SQL injection vulnerability in read.php in Open Bulletin Board (OpenBB) 1.0.8 allows remote attackers to execute arbitrary SQL commands via
HighCVSS 7.5Proof of conceptEPSS 2%openbb · openbbMay 16, 2005
- CVE-2004-196930Monitor
The avatar upload capability in Open Bulletin Board (OpenBB) 1.0.6 and earlier allows remote attackers to execute arbitrary script by upload
HighCVSS 7.5No exploitEPSS 2%openbb · openbbApr 25, 2004
- CVE-2004-196630Monitor
Multiple SQL injection vulnerabilities in Open Bulletin Board (OpenBB) 1.0.6 and earlier allow remote attackers to execute arbitrary SQL com
HighCVSS 7.5Proof of conceptEPSS 1%openbb · openbbDec 31, 2004
- CVE-2005-256630Monitor
Multiple SQL injection vulnerabilities in Open Bulletin Board (OpenBB) allow remote attackers to execute arbitrary SQL commands via the (1)
HighCVSS 7.5No exploitEPSS 1%openbb · openbbAug 16, 2005
- CVE-2005-161328Monitor
Cross-site scripting (XSS) vulnerability in member.php in Open Bulletin Board (OpenBB) 1.0.8 allows remote attackers to inject arbitrary web
MediumCVSS 6.8Proof of conceptEPSS 4%openbb · openbbMay 16, 2005
- CVE-2002-183022Monitor
Open Bulletin Board (OpenBB) 1.0.0 RC3 allows remote attackers to bypass authentication and access modifier options via a direct request to
MediumCVSS 5.0Proof of conceptEPSS 7%openbb · openbbDec 31, 2002
- CVE-2004-196821Monitor
The readmsg action in myhome.php in Open Bulletin Board (OpenBB) 1.0.6 and earlier allows remote attackers to read arbitrary messages by mod
MediumCVSS 5.0Proof of conceptEPSS 3%openbb · openbbApr 26, 2004
- CVE-2004-196520Monitor
Multiple cross-site scripting (XSS) vulnerabilities in Open Bulletin Board (OpenBB) 1.0.6 and earlier allows remote attackers to inject arbi
MediumCVSS 4.3Proof of conceptEPSS 9%openbb · openbbApr 25, 2004
- CVE-2002-182918Monitor
Cross-site scripting (XSS) vulnerability in codeparse.php in Open Bulletin Board (OpenBB) 1.0.0 RC3 allows remote attackers to inject arbitr
MediumCVSS 4.3Proof of conceptEPSS 4%openbb · openbbDec 31, 2002