ubbcentral records
20 published records for vendor ubbcentral.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 11
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
20 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
32Monitor | CVE-2008-6970Proof of concept | SQL injection vulnerability in dosearch.inc.php in UBB.threads 7.3.1 and earlier allows remote attackers to execute arbitrary SQL commands vubbcentral · ubb.threads · CWE-89 | High7.5 | — | 7.3% | Aug 13, 2009 |
31Monitor | CVE-2004-1622Proof of concept | SQL injection vulnerability in dosearch.php in UBB.threads 3.4.x allows remote attackers to execute arbitrary SQL statements via the Name paubbcentral · ubb.threads | High7.5 | — | 2.4% | Oct 21, 2004 |
30Monitor | CVE-2006-5136No exploit | Multiple PHP remote file inclusion vulnerabilities in ubbt.inc.php in Groupee UBB.threads 6.5.1.1 allow remote attackers to execute arbitrarubbcentral · ubb.threads | High7.5 | — | 1.6% | Oct 3, 2006 |
30Monitor | CVE-2006-0545Proof of concept | SQL injection vulnerability in showflat.php in Groupee (formerly known as Infopop) UBB.threads 6.3 and earlier allows remote attackers to exubbcentral · ubb.threads | High7.5 | — | 1.3% | Feb 3, 2006 |
30Monitor | CVE-2005-2058Proof of concept | Multiple SQL injection vulnerabilities in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to execute arbitrary SQL commands viaubbcentral · ubb.threads | High7.5 | — | 1.2% | Jun 29, 2005 |
30Monitor | CVE-2005-0726No exploit | SQL injection vulnerability in editpost.php in UBB.threads 6.0 allows remote attackers to execute arbitrary SQL commands via the Number paraubbcentral · ubb.threads | High7.5 | — | 1.2% | May 2, 2005 |
30Monitor | CVE-2007-1956Proof of concept | SQL injection vulnerability in ubbthreads.php in Groupee UBB.threads 6.1.1 and earlier allows remote attackers to execute arbitrary SQL commubbcentral · ubb.threads | High7.5 | — | 1.0% | Apr 10, 2007 |
27Monitor | CVE-2005-2057No exploit | Multiple cross-site scripting (XSS) vulnerabilities in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to inject arbitrary web ubbcentral · ubb.threads | Medium6.8 | — | 1.5% | Jun 29, 2005 |
26Monitor | CVE-2005-2059No exploit | Multiple cross-site request forgery (CSRF) vulnerabilities in (1) addaddress.php, (2) toggleignore.php, (3) removeignore.php, and (4) removeubbcentral · ubb.threads · CWE-352 | Medium6.5 | — | 1.0% | Jun 29, 2005 |
22Monitor | CVE-2006-2568Proof of concept | PHP remote file inclusion vulnerability in addpost_newpoll.php in UBB.threads 6.4 through 6.5.2 and 6.5.1.1 (trial) allows remote attackers ubbcentral · ubb.threads | Medium5.1 | — | 7.9% | May 24, 2006 |
21Monitor | CVE-2006-2675Proof of concept | PHP remote file inclusion vulnerability in ubbt.inc.php in UBBThreads 5.x and 6.x allows remote attackers to execute arbitrary PHP code via ubbcentral · ubb.threads | Medium5.1 | — | 2.5% | May 30, 2006 |
21Monitor | CVE-2006-5137Proof of concept | Multiple direct static code injection vulnerabilities in Groupee UBB.threads 6.5.1.1 allow remote attackers to (1) inject PHP code via a theubbcentral · ubb.threads | Medium5.1 | — | 2.2% | Oct 3, 2006 |
20Monitor | CVE-2006-5138No exploit | Groupee UBB.threads 6.5.1.1 allows remote attackers to obtain sensitive information via a direct request for cron/php/subscriptions.php, whiubbcentral · ubb.threads | Medium5.0 | — | 1.5% | Oct 3, 2006 |
20Monitor | CVE-2005-2061No exploit | Infopop UBB.Threads before 6.5.2 Beta allows remote attackers to include arbitrary files via the language parameter in a cookie followed by ubbcentral · ubb.threads | Medium5.0 | — | 1.3% | Jun 29, 2005 |
20Monitor | CVE-2005-2060No exploit | Multiple HTTP Response Splitting vulnerabilities in (1) toggleshow.php, (2) togglecats.php, and (3) showprofile.php in Infopop UBB.Threads bubbcentral · ubb.threads | Medium5.0 | — | 1.3% | Jun 29, 2005 |
20Monitor | CVE-2006-1423No exploit | SQL injection vulnerability in showflat.php in UBB.threads 5.5.1, 6.0 br5, 6.0.1, 6.0.2, and earlier, allows remote attackers to execute arbubbcentral · ubb.threads · CWE-89 | Medium5.0 | — | 1.0% | Mar 28, 2006 |
18Monitor | CVE-2004-2510Proof of concept | Cross-site scripting (XSS) vulnerability in showflat.php in Infopop UBB.Threads before 6.5 allows remote attackers to inject arbitrary web subbcentral · ubb.threads | Medium4.3 | — | 3.9% | Dec 31, 2004 |
18Monitor | CVE-2006-2755Proof of concept | Cross-site scripting (XSS) vulnerability in index.php in UBBThreads 5.x and earlier allows remote attackers to inject arbitrary web script oubbcentral · ubb.threads | Medium4.3 | — | 2.3% | Jun 1, 2006 |
18Monitor | CVE-2004-2509Proof of concept | Cross-site scripting (XSS) vulnerabilities in (1) calendar.php, (2) login.php, and (3) online.php in Infopop UBB.Threads 6.2.3 and 6.5 allowubbcentral · ubb.threads | Medium4.3 | — | 2.2% | Dec 31, 2004 |
18Monitor | CVE-2012-5104Proof of concept | Cross-site scripting (XSS) vulnerability in forums/ubbthreads.php in UBB.threads 7.5.6 and earlier allows remote attackers to inject arbitraubbcentral · ubb.threads · CWE-79 | Medium4.3 | — | 2.0% | Sep 23, 2012 |
- CVE-2008-697032Monitor
SQL injection vulnerability in dosearch.inc.php in UBB.threads 7.3.1 and earlier allows remote attackers to execute arbitrary SQL commands v
HighCVSS 7.5Proof of conceptEPSS 7%ubbcentral · ubb.threadsAug 13, 2009
- CVE-2004-162231Monitor
SQL injection vulnerability in dosearch.php in UBB.threads 3.4.x allows remote attackers to execute arbitrary SQL statements via the Name pa
HighCVSS 7.5Proof of conceptEPSS 2%ubbcentral · ubb.threadsOct 21, 2004
- CVE-2006-513630Monitor
Multiple PHP remote file inclusion vulnerabilities in ubbt.inc.php in Groupee UBB.threads 6.5.1.1 allow remote attackers to execute arbitrar
HighCVSS 7.5No exploitEPSS 2%ubbcentral · ubb.threadsOct 3, 2006
- CVE-2006-054530Monitor
SQL injection vulnerability in showflat.php in Groupee (formerly known as Infopop) UBB.threads 6.3 and earlier allows remote attackers to ex
HighCVSS 7.5Proof of conceptEPSS 1%ubbcentral · ubb.threadsFeb 3, 2006
- CVE-2005-205830Monitor
Multiple SQL injection vulnerabilities in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to execute arbitrary SQL commands via
HighCVSS 7.5Proof of conceptEPSS 1%ubbcentral · ubb.threadsJun 29, 2005
- CVE-2005-072630Monitor
SQL injection vulnerability in editpost.php in UBB.threads 6.0 allows remote attackers to execute arbitrary SQL commands via the Number para
HighCVSS 7.5No exploitEPSS 1%ubbcentral · ubb.threadsMay 2, 2005
- CVE-2007-195630Monitor
SQL injection vulnerability in ubbthreads.php in Groupee UBB.threads 6.1.1 and earlier allows remote attackers to execute arbitrary SQL comm
HighCVSS 7.5Proof of conceptEPSS 1%ubbcentral · ubb.threadsApr 10, 2007
- CVE-2005-205727Monitor
Multiple cross-site scripting (XSS) vulnerabilities in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to inject arbitrary web
MediumCVSS 6.8No exploitEPSS 1%ubbcentral · ubb.threadsJun 29, 2005
- CVE-2005-205926Monitor
Multiple cross-site request forgery (CSRF) vulnerabilities in (1) addaddress.php, (2) toggleignore.php, (3) removeignore.php, and (4) remove
MediumCVSS 6.5No exploitEPSS 1%ubbcentral · ubb.threadsJun 29, 2005
- CVE-2006-256822Monitor
PHP remote file inclusion vulnerability in addpost_newpoll.php in UBB.threads 6.4 through 6.5.2 and 6.5.1.1 (trial) allows remote attackers
MediumCVSS 5.1Proof of conceptEPSS 8%ubbcentral · ubb.threadsMay 24, 2006
- CVE-2006-267521Monitor
PHP remote file inclusion vulnerability in ubbt.inc.php in UBBThreads 5.x and 6.x allows remote attackers to execute arbitrary PHP code via
MediumCVSS 5.1Proof of conceptEPSS 3%ubbcentral · ubb.threadsMay 30, 2006
- CVE-2006-513721Monitor
Multiple direct static code injection vulnerabilities in Groupee UBB.threads 6.5.1.1 allow remote attackers to (1) inject PHP code via a the
MediumCVSS 5.1Proof of conceptEPSS 2%ubbcentral · ubb.threadsOct 3, 2006
- CVE-2006-513820Monitor
Groupee UBB.threads 6.5.1.1 allows remote attackers to obtain sensitive information via a direct request for cron/php/subscriptions.php, whi
MediumCVSS 5.0No exploitEPSS 1%ubbcentral · ubb.threadsOct 3, 2006
- CVE-2005-206120Monitor
Infopop UBB.Threads before 6.5.2 Beta allows remote attackers to include arbitrary files via the language parameter in a cookie followed by
MediumCVSS 5.0No exploitEPSS 1%ubbcentral · ubb.threadsJun 29, 2005
- CVE-2005-206020Monitor
Multiple HTTP Response Splitting vulnerabilities in (1) toggleshow.php, (2) togglecats.php, and (3) showprofile.php in Infopop UBB.Threads b
MediumCVSS 5.0No exploitEPSS 1%ubbcentral · ubb.threadsJun 29, 2005
- CVE-2006-142320Monitor
SQL injection vulnerability in showflat.php in UBB.threads 5.5.1, 6.0 br5, 6.0.1, 6.0.2, and earlier, allows remote attackers to execute arb
MediumCVSS 5.0No exploitEPSS 1%ubbcentral · ubb.threadsMar 28, 2006
- CVE-2004-251018Monitor
Cross-site scripting (XSS) vulnerability in showflat.php in Infopop UBB.Threads before 6.5 allows remote attackers to inject arbitrary web s
MediumCVSS 4.3Proof of conceptEPSS 4%ubbcentral · ubb.threadsDec 31, 2004
- CVE-2006-275518Monitor
Cross-site scripting (XSS) vulnerability in index.php in UBBThreads 5.x and earlier allows remote attackers to inject arbitrary web script o
MediumCVSS 4.3Proof of conceptEPSS 2%ubbcentral · ubb.threadsJun 1, 2006
- CVE-2004-250918Monitor
Cross-site scripting (XSS) vulnerabilities in (1) calendar.php, (2) login.php, and (3) online.php in Infopop UBB.Threads 6.2.3 and 6.5 allow
MediumCVSS 4.3Proof of conceptEPSS 2%ubbcentral · ubb.threadsDec 31, 2004
- CVE-2012-510418Monitor
Cross-site scripting (XSS) vulnerability in forums/ubbthreads.php in UBB.threads 7.5.6 and earlier allows remote attackers to inject arbitra
MediumCVSS 4.3Proof of conceptEPSS 2%ubbcentral · ubb.threadsSep 23, 2012