Skip to content
Noroxi

UseBB records

12 published records for vendor usebb.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
2
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

  1. 20

Bar: total · dark part: CISA KEV.

All records

12 records
  • CVE-2020-8088
    39Monitor

    panel_login.php in UseBB 1.0.12 allows type juggling for login bypass because != is used instead of !== for password hashes, which mishandle

    CriticalCVSS 9.8No exploitEPSS 1%

    usebb · usebbJan 27, 2020

  • CVE-2007-3963
    38Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in UseBB 1.0.7, and possibly other 1.0.x versions, allow remote attackers to inject arbi

    CriticalCVSS 9.3Proof of conceptEPSS 2%

    usebb · usebbJul 25, 2007

  • CVE-2011-3612
    35Monitor

    Cross-Site Request Forgery (CSRF) vulnerability exists in panel.php in UseBB before 1.0.12.

    HighCVSS 8.8No exploitEPSS 1%

    usebb · usebbJan 22, 2020

  • CVE-2005-2439
    30Monitor

    SQL injection vulnerability in UseBB 0.5.1 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL

    HighCVSS 7.5No exploitEPSS 1%

    usebb · usebbAug 3, 2005

  • CVE-2011-3611
    29Monitor

    A File Inclusion vulnerability exists in act parameter to admin.php in UseBB before 1.0.12.

    HighCVSS 7.2No exploitEPSS 3%

    usebb · usebbJan 22, 2020

  • CVE-2006-2524
    27Monitor

    Cross-site scripting (XSS) vulnerability in UseBB 1.0 RC1 and earlier allows remote attackers to inject arbitrary web script or HTML via uns

    MediumCVSS 6.8No exploitEPSS 1%

    usebb · usebbMay 22, 2006

  • CVE-2006-2525
    25Monitor

    SQL injection vulnerability in UseBB 1.0 RC1 and earlier allows remote attackers to execute arbitrary SQL commands via the member list searc

    MediumCVSS 6.4No exploitEPSS 1%

    usebb · usebbMay 22, 2006

  • CVE-2009-4041
    21Monitor

    UseBB 1.0.9 before 1.0.10 allows remote attackers to cause a denial of service (infinite loop) via crafted BBCode tags.

    MediumCVSS 5.0No exploitEPSS 2%

    usebb · usebbNov 20, 2009

  • CVE-2007-2066
    20Monitor

    UseBB before 1.0.6 allows remote attackers to obtain sensitive information via a request with unspecified GET or POST parameters to an unspe

    MediumCVSS 5.0No exploitEPSS 1%

    usebb · usebbApr 17, 2007

  • CVE-2005-2438
    17Monitor

    Cross-site scripting (XSS) vulnerability in UseBB 0.5.1 and earlier allows remote attackers to inject arbitrary Javascript via the BBCode co

    MediumCVSS 4.3No exploitEPSS 1%

    usebb · usebbAug 3, 2005

  • CVE-2005-4193
    17Monitor

    Cross-site scripting (XSS) vulnerability in UseBB before 0.7 allows remote attackers to inject arbitrary web script or HTML via the $_SERVER

    MediumCVSS 4.3No exploitEPSS 1%

    usebb · usebbDec 13, 2005

  • CVE-2010-3713
    17Monitor

    rss.php in UseBB before 1.0.11 does not properly handle forum configurations in which a user has the view permission but not the read permis

    MediumCVSS 4.3No exploitEPSS 1%

    usebb · usebbOct 27, 2010