phpbb group records
93 published records for vendor phpbb group.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 2 · 2.2%
- Pre-auth RCE
- 28
- With a fix record
- 17.2%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-20 Improper Input Validation1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
93 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
56Plan | CVE-2005-2086Weaponized | PHP remote file inclusion vulnerability in viewtopic.php in phpBB 2.0.15 and earlier allows remote attackers to execute arbitrary PHP code.phpbb group · phpbb | High7.5 | — | 85.4% | Jul 5, 2005 |
52Plan | CVE-2004-1315Weaponized | viewtopic.php in phpBB 2.x before 2.0.11 improperly URL decodes the highlight parameter when extracting words and phrases to highlight, whicphpbb group · phpbb | High7.5 | — | 72.1% | Nov 12, 2004 |
42Plan | CVE-2002-0473No exploit | db.php in phpBB 2.0 (aka phpBB2) RC-3 and earlier allows remote attackers to execute arbitrary code from remote servers via the phpbb_root_pphpbb group · phpbb | Critical10.0 | — | 5.3% | Aug 12, 2002 |
41Plan | CVE-2002-2176Proof of concept | SQL injection vulnerability in Gender MOD 1.1.3 allows remote attackers to gain administrative access via the user_level parameter in the Usphpbb group · phpbb | Critical10.0 | — | 3.3% | Dec 31, 2002 |
41Plan | CVE-2002-1537No exploit | admin_ug_auth.php in phpBB 2.0.0 allows local users to gain administrator privileges by directly calling admin_ug_auth.php with modifed formphpbb group · phpbb | Critical10.0 | — | 2.5% | Mar 31, 2003 |
41Plan | CVE-2007-1695No exploit | PHP remote file inclusion vulnerability in includes/usercp_register.php in phpBB 2.0.19 allows remote attackers to execute arbitrary PHP codphpbb group · phpbb | Critical10.0 | — | 1.9% | Mar 26, 2007 |
40Plan | CVE-2006-6840No exploit | Unspecified vulnerability in phpBB before 2.0.22 has unknown impact and remote attack vectors related to a "negative start parameter."phpbb group · phpbb | Critical10.0 | — | 1.6% | Dec 31, 2006 |
40Plan | CVE-2006-6839No exploit | Unspecified vulnerability in phpBB before 2.0.22 has unknown impact and remote attack vectors related to "criteria for 'bad' redirection tarphpbb group · phpbb | Critical10.0 | — | 1.6% | Dec 31, 2006 |
40Plan | CVE-2006-6841No exploit | Certain forms in phpBB before 2.0.22 lack session checks, which has unknown impact and remote attack vectors.phpbb group · phpbb | Critical10.0 | — | 1.6% | Dec 31, 2006 |
35Monitor | CVE-2005-1193Proof of concept | The bbencode_second_pass and make_clickable functions in bbcode.php for phpBB before 2.0.15, as used in viewtopic.php, privmsg.php, and othephpbb group · phpbb | High7.5 | — | 16.4% | May 16, 2005 |
33Monitor | CVE-2006-2151Proof of concept | PHP remote file inclusion vulnerability in toplist.php in phpBB TopList 1.3.8 and earlier, when register_globals is enabled, allows remote aphpbb group · phpbb toplist | High7.5 | — | 11.0% | May 3, 2006 |
33Monitor | CVE-2006-2152Proof of concept | PHP remote file inclusion vulnerability in admin/addentry.php in phpBB Advanced Guestbook 2.4.0 and earlier, when register_globals is enablephpbb group · phpbb advanced guestbook | High7.5 | — | 8.3% | May 3, 2006 |
32Monitor | CVE-2005-0614Proof of concept | sessions.php in phpBB 2.0.12 and earlier allows remote attackers to gain administrator privileges via the autologinid value in a cookie.phpbb group · phpbb | High7.5 | — | 7.6% | May 2, 2005 |
32Monitor | CVE-2002-0902Proof of concept | Cross-site scripting vulnerability in phpBB 2.0.0 (phpBB2) allows remote attackers to execute Javascript as other phpBB users by including aphpbb group · phpbb | High7.5 | — | 7.2% | Oct 4, 2002 |
32Monitor | CVE-2004-1535Proof of concept | PHP remote file inclusion vulnerability in admin_cash.php for the Cash Mod module for phpBB allows remote attackers to execute arbitrary PHPphpbb group · phpbb | High7.5 | — | 6.3% | Dec 31, 2004 |
31Monitor | CVE-2006-4779Proof of concept | PHP remote file inclusion vulnerability in includes/functions_portal.php in Vitrax Premodded phpBB 1.0.6-R3 and earlier allows remote attackphpbb group · vitrax premodded phpbb | High7.5 | — | 2.9% | Sep 14, 2006 |
31Monitor | CVE-2006-2865Proof of concept | PHP remote file inclusion vulnerability in template.php in phpBB 2 allows remote attackers to execute arbitrary PHP code via a URL in the paphpbb group · phpbb | High7.5 | — | 2.8% | Jun 6, 2006 |
31Monitor | CVE-2004-1943Proof of concept | PHP remote file inclusion vulnerability in album_portal.php in phpBB modified by Przemo 1.8 allows remote attackers to execute arbitrary PHPphpbb group · phpbb | High7.5 | — | 2.6% | Apr 19, 2004 |
31Monitor | CVE-2005-3415No exploit | phpBB 2.0.17 and earlier allows remote attackers to bypass protection mechanisms that deregister global variables by setting both a GET/POSTphpbb group · phpbb | High7.5 | — | 2.4% | Nov 1, 2005 |
31Monitor | CVE-2005-3420No exploit | usercp_register.php in phpBB 2.0.17 allows remote attackers to modify regular expressions and execute PHP code via the signature_bbcode_uid phpbb group · phpbb | High7.5 | — | 2.4% | Nov 1, 2005 |
31Monitor | CVE-2005-3417No exploit | phpBB 2.0.17 and earlier, when the register_long_arrays directive is disabled, allows remote attackers to modify global variables and bypassphpbb group · phpbb | High7.5 | — | 2.3% | Nov 1, 2005 |
31Monitor | CVE-2005-3416No exploit | phpBB 2.0.17 and earlier, when register_globals is enabled and the session_start function has not been called to handle a session, allows rephpbb group · phpbb | High7.5 | — | 2.3% | Nov 1, 2005 |
31Monitor | CVE-2006-5209Proof of concept | PHP remote file inclusion vulnerability in admin/admin_topic_action_logging.php in Admin Topic Action Logging Mod 0.95 and earlier, as used phpbb group · phpbb | High7.5 | — | 2.3% | Oct 10, 2006 |
31Monitor | CVE-2005-1047No exploit | Meilad File upload script (up.php) mod for phpBB 2.0.x does not properly limit the types of files that can be uploaded, which allows remote phpbb group · phpbb | High7.5 | — | 2.1% | Apr 7, 2005 |
31Monitor | CVE-2005-1196Proof of concept | SQL injection vulnerability in kb.php in the Knowledge Base module for phpBB allows remote attackers to obtain sensitive information and exephpbb group · phpbb | High7.5 | — | 2.0% | May 2, 2005 |
- CVE-2005-208656Plan
PHP remote file inclusion vulnerability in viewtopic.php in phpBB 2.0.15 and earlier allows remote attackers to execute arbitrary PHP code.
HighCVSS 7.5WeaponizedEPSS 85%phpbb group · phpbbJul 5, 2005
- CVE-2004-131552Plan
viewtopic.php in phpBB 2.x before 2.0.11 improperly URL decodes the highlight parameter when extracting words and phrases to highlight, whic
HighCVSS 7.5WeaponizedEPSS 72%phpbb group · phpbbNov 12, 2004
- CVE-2002-047342Plan
db.php in phpBB 2.0 (aka phpBB2) RC-3 and earlier allows remote attackers to execute arbitrary code from remote servers via the phpbb_root_p
CriticalCVSS 10.0No exploitEPSS 5%phpbb group · phpbbAug 12, 2002
- CVE-2002-217641Plan
SQL injection vulnerability in Gender MOD 1.1.3 allows remote attackers to gain administrative access via the user_level parameter in the Us
CriticalCVSS 10.0Proof of conceptEPSS 3%phpbb group · phpbbDec 31, 2002
- CVE-2002-153741Plan
admin_ug_auth.php in phpBB 2.0.0 allows local users to gain administrator privileges by directly calling admin_ug_auth.php with modifed form
CriticalCVSS 10.0No exploitEPSS 2%phpbb group · phpbbMar 31, 2003
- CVE-2007-169541Plan
PHP remote file inclusion vulnerability in includes/usercp_register.php in phpBB 2.0.19 allows remote attackers to execute arbitrary PHP cod
CriticalCVSS 10.0No exploitEPSS 2%phpbb group · phpbbMar 26, 2007
- CVE-2006-684040Plan
Unspecified vulnerability in phpBB before 2.0.22 has unknown impact and remote attack vectors related to a "negative start parameter."
CriticalCVSS 10.0No exploitEPSS 2%phpbb group · phpbbDec 31, 2006
- CVE-2006-683940Plan
Unspecified vulnerability in phpBB before 2.0.22 has unknown impact and remote attack vectors related to "criteria for 'bad' redirection tar
CriticalCVSS 10.0No exploitEPSS 2%phpbb group · phpbbDec 31, 2006
- CVE-2006-684140Plan
Certain forms in phpBB before 2.0.22 lack session checks, which has unknown impact and remote attack vectors.
CriticalCVSS 10.0No exploitEPSS 2%phpbb group · phpbbDec 31, 2006
- CVE-2005-119335Monitor
The bbencode_second_pass and make_clickable functions in bbcode.php for phpBB before 2.0.15, as used in viewtopic.php, privmsg.php, and othe
HighCVSS 7.5Proof of conceptEPSS 16%phpbb group · phpbbMay 16, 2005
- CVE-2006-215133Monitor
PHP remote file inclusion vulnerability in toplist.php in phpBB TopList 1.3.8 and earlier, when register_globals is enabled, allows remote a
HighCVSS 7.5Proof of conceptEPSS 11%phpbb group · phpbb toplistMay 3, 2006
- CVE-2006-215233Monitor
PHP remote file inclusion vulnerability in admin/addentry.php in phpBB Advanced Guestbook 2.4.0 and earlier, when register_globals is enable
HighCVSS 7.5Proof of conceptEPSS 8%phpbb group · phpbb advanced guestbookMay 3, 2006
- CVE-2005-061432Monitor
sessions.php in phpBB 2.0.12 and earlier allows remote attackers to gain administrator privileges via the autologinid value in a cookie.
HighCVSS 7.5Proof of conceptEPSS 8%phpbb group · phpbbMay 2, 2005
- CVE-2002-090232Monitor
Cross-site scripting vulnerability in phpBB 2.0.0 (phpBB2) allows remote attackers to execute Javascript as other phpBB users by including a
HighCVSS 7.5Proof of conceptEPSS 7%phpbb group · phpbbOct 4, 2002
- CVE-2004-153532Monitor
PHP remote file inclusion vulnerability in admin_cash.php for the Cash Mod module for phpBB allows remote attackers to execute arbitrary PHP
HighCVSS 7.5Proof of conceptEPSS 6%phpbb group · phpbbDec 31, 2004
- CVE-2006-477931Monitor
PHP remote file inclusion vulnerability in includes/functions_portal.php in Vitrax Premodded phpBB 1.0.6-R3 and earlier allows remote attack
HighCVSS 7.5Proof of conceptEPSS 3%phpbb group · vitrax premodded phpbbSep 14, 2006
- CVE-2006-286531Monitor
PHP remote file inclusion vulnerability in template.php in phpBB 2 allows remote attackers to execute arbitrary PHP code via a URL in the pa
HighCVSS 7.5Proof of conceptEPSS 3%phpbb group · phpbbJun 6, 2006
- CVE-2004-194331Monitor
PHP remote file inclusion vulnerability in album_portal.php in phpBB modified by Przemo 1.8 allows remote attackers to execute arbitrary PHP
HighCVSS 7.5Proof of conceptEPSS 3%phpbb group · phpbbApr 19, 2004
- CVE-2005-341531Monitor
phpBB 2.0.17 and earlier allows remote attackers to bypass protection mechanisms that deregister global variables by setting both a GET/POST
HighCVSS 7.5No exploitEPSS 2%phpbb group · phpbbNov 1, 2005
- CVE-2005-342031Monitor
usercp_register.php in phpBB 2.0.17 allows remote attackers to modify regular expressions and execute PHP code via the signature_bbcode_uid
HighCVSS 7.5No exploitEPSS 2%phpbb group · phpbbNov 1, 2005
- CVE-2005-341731Monitor
phpBB 2.0.17 and earlier, when the register_long_arrays directive is disabled, allows remote attackers to modify global variables and bypass
HighCVSS 7.5No exploitEPSS 2%phpbb group · phpbbNov 1, 2005
- CVE-2005-341631Monitor
phpBB 2.0.17 and earlier, when register_globals is enabled and the session_start function has not been called to handle a session, allows re
HighCVSS 7.5No exploitEPSS 2%phpbb group · phpbbNov 1, 2005
- CVE-2006-520931Monitor
PHP remote file inclusion vulnerability in admin/admin_topic_action_logging.php in Admin Topic Action Logging Mod 0.95 and earlier, as used
HighCVSS 7.5Proof of conceptEPSS 2%phpbb group · phpbbOct 10, 2006
- CVE-2005-104731Monitor
Meilad File upload script (up.php) mod for phpBB 2.0.x does not properly limit the types of files that can be uploaded, which allows remote
HighCVSS 7.5No exploitEPSS 2%phpbb group · phpbbApr 7, 2005
- CVE-2005-119631Monitor
SQL injection vulnerability in kb.php in the Knowledge Base module for phpBB allows remote attackers to obtain sensitive information and exe
HighCVSS 7.5Proof of conceptEPSS 2%phpbb group · phpbbMay 2, 2005