woltlab records
46 published records for vendor woltlab.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 27
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')6
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
46 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
31Monitor | CVE-2006-6237Proof of concept | SQL injection vulnerability in the decode_cookie function in thread.php in Woltlab Burning Board Lite 1.0.2 allows remote attackers to execuwoltlab · burning board lite | High7.5 | — | 2.6% | Dec 3, 2006 |
31Monitor | CVE-2002-1505Proof of concept | SQL injection vulnerability in board.php for WoltLab Burning Board (wBB) 2.0 RC 1 and earlier allows remote attackers to modify the databasewoltlab · burning board | High7.5 | — | 2.4% | Apr 2, 2003 |
31Monitor | CVE-2006-1094Proof of concept | SQL injection vulnerability in Datenbank MOD 2.7 and earlier for Woltlab Burning Board allows remote attackers to execute arbitrary SQL commwoltlab · burning board | High7.5 | — | 2.4% | Mar 9, 2006 |
31Monitor | CVE-2007-6518Proof of concept | Multiple SQL injection vulnerabilities in search.php in WoltLab Burning Board (wBB) Lite 1.0.2 pl3e allow remote attackers to execute arbitrwoltlab · burning board lite · CWE-89 | High7.5 | — | 2.3% | Dec 24, 2007 |
31Monitor | CVE-2002-0903No exploit | register.php for WoltLab Burning Board (wbboard) 1.1.1 uses a small number of random values for the "code" parameter that is provided to actwoltlab · burning board | High7.5 | — | 1.8% | Oct 4, 2002 |
30Monitor | CVE-2010-1338Proof of concept | SQL injection vulnerability in ts_other.php in the Teamsite Hack plugin 3.0 and earlier for WoltLab Burning Board allows remote attackers towoltlab · burning board · CWE-89 | High7.5 | — | 1.6% | Apr 9, 2010 |
30Monitor | CVE-2005-3369Proof of concept | Multiple SQL injection vulnerabilities in the Info-DB module (info_db.php) in Woltlab Burning Board 2.7 and earlier allow remote attackers twoltlab · burning board | High7.5 | — | 1.3% | Oct 30, 2005 |
30Monitor | CVE-2005-1642Proof of concept | SQL injection vulnerability in the verify_email function in Woltlab Burning Board 2.x and earlier allows remote attackers to execute arbitrawoltlab · burning board | High7.5 | — | 1.3% | May 17, 2005 |
30Monitor | CVE-2007-0812Proof of concept | SQL injection vulnerability in pms.php in Woltlab Burning Board (wBB) Lite 1.0.2pl3e and earlier allows remote authenticated users to executwoltlab · burning board lite | High7.5 | — | 1.3% | Feb 7, 2007 |
30Monitor | CVE-2006-5509Proof of concept | Eval injection vulnerability in addentry.php in WoltLab Burning Book 1.1.2 allows remote attackers to execute arbitrary PHP code via craftedwoltlab · burning book | High7.5 | — | 1.3% | Oct 25, 2006 |
30Monitor | CVE-2006-2792No exploit | SQL injection vulnerability in misc.php in Woltlab Burning Board (WBB) 2.3.4 allows remote attackers to execute arbitrary SQL commands via twoltlab · burning board | High7.5 | — | 1.2% | Jun 2, 2006 |
30Monitor | CVE-2006-3218No exploit | SQL injection vulnerability in profile.php in Woltlab Burning Board (WBB) 2.1.6 allows remote attackers to execute arbitrary SQL commands viwoltlab · burning board | High7.5 | — | 1.2% | Jun 24, 2006 |
30Monitor | CVE-2006-3219No exploit | SQL injection vulnerability in thread.php in Woltlab Burning Board (WBB) 2.2.2 allows remote attackers to execute arbitrary SQL commands viawoltlab · burning board | High7.5 | — | 1.2% | Jun 24, 2006 |
30Monitor | CVE-2006-3220No exploit | SQL injection vulnerability in studienplatztausch.php in Woltlab Burning Board (WBB) 2.2.1 allows remote attackers to execute arbitrary SQL woltlab · burning board | High7.5 | — | 1.2% | Jun 24, 2006 |
30Monitor | CVE-2006-5029No exploit | SQL injection vulnerability in thread.php in WoltLab Burning Board (wBB) 2.3.x allows remote attackers to obtain the version numbers of PHP,woltlab · burning board | High7.5 | — | 1.2% | Sep 27, 2006 |
30Monitor | CVE-2006-2569Proof of concept | SQL injection vulnerability in links.php in 4R Linklist 1.0 RC2 and earlier, a module for Woltlab Burning Board, allows remote attackers to 4r linklist · 4r linklist | High7.5 | — | 1.1% | May 24, 2006 |
30Monitor | CVE-2006-3256Proof of concept | SQL injection vulnerability in report.php in Woltlab Burning Board (WBB) 2.3.1 allows remote attackers to execute arbitrary SQL commands viawoltlab · burning board | High7.5 | — | 1.1% | Jun 27, 2006 |
30Monitor | CVE-2006-3254Proof of concept | SQL injection vulnerability in newthread.php in Woltlab Burning Board (WBB) 2.0 RC2 allows remote attackers to execute arbitrary SQL commandwoltlab · burning board | High7.5 | — | 1.1% | Jun 27, 2006 |
30Monitor | CVE-2006-3255Proof of concept | SQL injection vulnerability in showmods.php in Woltlab Burning Board (WBB) 1.2 allows remote attackers to execute arbitrary SQL commands viawoltlab · burning board | High7.5 | — | 1.1% | Jun 27, 2006 |
30Monitor | CVE-2005-0284No exploit | SQL injection vulnerability in addentry.php in Woltlab Burning Book 1.0 Gold, 1.1.1e, and possibly other versions, allows remote attackers twoltlab · burning book | High7.5 | — | 1.1% | Jan 10, 2005 |
30Monitor | CVE-2005-0661No exploit | SQL injection vulnerability in the getwbbuserdata function in session.php for Woltlab Burning Board 2.0.3 through 2.3.0 allows remote attackwoltlab · burning board | High7.5 | — | 1.1% | May 2, 2005 |
30Monitor | CVE-2006-5508Proof of concept | Multiple SQL injection vulnerabilities in addentry.php in WoltLab Burning Book 1.1.2 allow remote attackers to execute arbitrary SQL commandwoltlab · burning book | High7.5 | — | 1.1% | Oct 25, 2006 |
30Monitor | CVE-2007-0388Proof of concept | SQL injection vulnerability in search.php in Woltlab Burning Board (wBB) 1.0.2 and earlier, and 2.3.6 and earlier in the 2.x series, allows woltlab · burning board | High7.5 | — | 1.1% | Jan 19, 2007 |
30Monitor | CVE-2005-2673Proof of concept | SQL injection vulnerability in modcp.php in WoltLab Burning Board 2.2.2 and 2.3.3 allows remote authenticated attackers to execute arbitrarywoltlab · burning board | High7.5 | — | 1.1% | Aug 23, 2005 |
30Monitor | CVE-2008-4627Proof of concept | SQL injection vulnerability in the rGallery plugin 1.09 for WoltLab Burning Board (WBB) allows remote attackers to execute arbitrary SQL comrgallery · rgallery plugin · CWE-89 | High7.5 | — | 1.0% | Oct 20, 2008 |
- CVE-2006-623731Monitor
SQL injection vulnerability in the decode_cookie function in thread.php in Woltlab Burning Board Lite 1.0.2 allows remote attackers to execu
HighCVSS 7.5Proof of conceptEPSS 3%woltlab · burning board liteDec 3, 2006
- CVE-2002-150531Monitor
SQL injection vulnerability in board.php for WoltLab Burning Board (wBB) 2.0 RC 1 and earlier allows remote attackers to modify the database
HighCVSS 7.5Proof of conceptEPSS 2%woltlab · burning boardApr 2, 2003
- CVE-2006-109431Monitor
SQL injection vulnerability in Datenbank MOD 2.7 and earlier for Woltlab Burning Board allows remote attackers to execute arbitrary SQL comm
HighCVSS 7.5Proof of conceptEPSS 2%woltlab · burning boardMar 9, 2006
- CVE-2007-651831Monitor
Multiple SQL injection vulnerabilities in search.php in WoltLab Burning Board (wBB) Lite 1.0.2 pl3e allow remote attackers to execute arbitr
HighCVSS 7.5Proof of conceptEPSS 2%woltlab · burning board liteDec 24, 2007
- CVE-2002-090331Monitor
register.php for WoltLab Burning Board (wbboard) 1.1.1 uses a small number of random values for the "code" parameter that is provided to act
HighCVSS 7.5No exploitEPSS 2%woltlab · burning boardOct 4, 2002
- CVE-2010-133830Monitor
SQL injection vulnerability in ts_other.php in the Teamsite Hack plugin 3.0 and earlier for WoltLab Burning Board allows remote attackers to
HighCVSS 7.5Proof of conceptEPSS 2%woltlab · burning boardApr 9, 2010
- CVE-2005-336930Monitor
Multiple SQL injection vulnerabilities in the Info-DB module (info_db.php) in Woltlab Burning Board 2.7 and earlier allow remote attackers t
HighCVSS 7.5Proof of conceptEPSS 1%woltlab · burning boardOct 30, 2005
- CVE-2005-164230Monitor
SQL injection vulnerability in the verify_email function in Woltlab Burning Board 2.x and earlier allows remote attackers to execute arbitra
HighCVSS 7.5Proof of conceptEPSS 1%woltlab · burning boardMay 17, 2005
- CVE-2007-081230Monitor
SQL injection vulnerability in pms.php in Woltlab Burning Board (wBB) Lite 1.0.2pl3e and earlier allows remote authenticated users to execut
HighCVSS 7.5Proof of conceptEPSS 1%woltlab · burning board liteFeb 7, 2007
- CVE-2006-550930Monitor
Eval injection vulnerability in addentry.php in WoltLab Burning Book 1.1.2 allows remote attackers to execute arbitrary PHP code via crafted
HighCVSS 7.5Proof of conceptEPSS 1%woltlab · burning bookOct 25, 2006
- CVE-2006-279230Monitor
SQL injection vulnerability in misc.php in Woltlab Burning Board (WBB) 2.3.4 allows remote attackers to execute arbitrary SQL commands via t
HighCVSS 7.5No exploitEPSS 1%woltlab · burning boardJun 2, 2006
- CVE-2006-321830Monitor
SQL injection vulnerability in profile.php in Woltlab Burning Board (WBB) 2.1.6 allows remote attackers to execute arbitrary SQL commands vi
HighCVSS 7.5No exploitEPSS 1%woltlab · burning boardJun 24, 2006
- CVE-2006-321930Monitor
SQL injection vulnerability in thread.php in Woltlab Burning Board (WBB) 2.2.2 allows remote attackers to execute arbitrary SQL commands via
HighCVSS 7.5No exploitEPSS 1%woltlab · burning boardJun 24, 2006
- CVE-2006-322030Monitor
SQL injection vulnerability in studienplatztausch.php in Woltlab Burning Board (WBB) 2.2.1 allows remote attackers to execute arbitrary SQL
HighCVSS 7.5No exploitEPSS 1%woltlab · burning boardJun 24, 2006
- CVE-2006-502930Monitor
SQL injection vulnerability in thread.php in WoltLab Burning Board (wBB) 2.3.x allows remote attackers to obtain the version numbers of PHP,
HighCVSS 7.5No exploitEPSS 1%woltlab · burning boardSep 27, 2006
- CVE-2006-256930Monitor
SQL injection vulnerability in links.php in 4R Linklist 1.0 RC2 and earlier, a module for Woltlab Burning Board, allows remote attackers to
HighCVSS 7.5Proof of conceptEPSS 1%4r linklist · 4r linklistMay 24, 2006
- CVE-2006-325630Monitor
SQL injection vulnerability in report.php in Woltlab Burning Board (WBB) 2.3.1 allows remote attackers to execute arbitrary SQL commands via
HighCVSS 7.5Proof of conceptEPSS 1%woltlab · burning boardJun 27, 2006
- CVE-2006-325430Monitor
SQL injection vulnerability in newthread.php in Woltlab Burning Board (WBB) 2.0 RC2 allows remote attackers to execute arbitrary SQL command
HighCVSS 7.5Proof of conceptEPSS 1%woltlab · burning boardJun 27, 2006
- CVE-2006-325530Monitor
SQL injection vulnerability in showmods.php in Woltlab Burning Board (WBB) 1.2 allows remote attackers to execute arbitrary SQL commands via
HighCVSS 7.5Proof of conceptEPSS 1%woltlab · burning boardJun 27, 2006
- CVE-2005-028430Monitor
SQL injection vulnerability in addentry.php in Woltlab Burning Book 1.0 Gold, 1.1.1e, and possibly other versions, allows remote attackers t
HighCVSS 7.5No exploitEPSS 1%woltlab · burning bookJan 10, 2005
- CVE-2005-066130Monitor
SQL injection vulnerability in the getwbbuserdata function in session.php for Woltlab Burning Board 2.0.3 through 2.3.0 allows remote attack
HighCVSS 7.5No exploitEPSS 1%woltlab · burning boardMay 2, 2005
- CVE-2006-550830Monitor
Multiple SQL injection vulnerabilities in addentry.php in WoltLab Burning Book 1.1.2 allow remote attackers to execute arbitrary SQL command
HighCVSS 7.5Proof of conceptEPSS 1%woltlab · burning bookOct 25, 2006
- CVE-2007-038830Monitor
SQL injection vulnerability in search.php in Woltlab Burning Board (wBB) 1.0.2 and earlier, and 2.3.6 and earlier in the 2.x series, allows
HighCVSS 7.5Proof of conceptEPSS 1%woltlab · burning boardJan 19, 2007
- CVE-2005-267330Monitor
SQL injection vulnerability in modcp.php in WoltLab Burning Board 2.2.2 and 2.3.3 allows remote authenticated attackers to execute arbitrary
HighCVSS 7.5Proof of conceptEPSS 1%woltlab · burning boardAug 23, 2005
- CVE-2008-462730Monitor
SQL injection vulnerability in the rGallery plugin 1.09 for WoltLab Burning Board (WBB) allows remote attackers to execute arbitrary SQL com
HighCVSS 7.5Proof of conceptEPSS 1%rgallery · rgallery pluginOct 20, 2008