Skip to content
Noroxi

sonicbb records

3 published records for vendor sonicbb.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

    Bar: total · dark part: CISA KEV.

    Recurring classes

      The weakness classes this vendor ships most often: where to look.

      CWE

      All records

      3 records
      • CVE-2007-1902
        27Monitor

        Multiple SQL injection vulnerabilities in SonicBB 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) part and (2) by p

        MediumCVSS 6.8Proof of conceptEPSS 2%

        sonicbb · sonicbbMay 14, 2007

      • CVE-2007-1901
        17Monitor

        SonicBB 1.0 allows remote attackers to obtain sensitive information via the (1) by[] parameter to search.php, (2) p[] parameter to viewforum

        MediumCVSS 4.3No exploitEPSS 2%

        sonicbb · sonicbbMay 14, 2007

      • CVE-2007-1903
        11Monitor

        Cross-site scripting (XSS) vulnerability in search.php in SonicBB 1.0 allows remote attackers to inject arbitrary web script or HTML via the

        LowCVSS 2.6Proof of conceptEPSS 2%

        sonicbb · sonicbbMay 14, 2007