Записи minibb
18 опубликованных записей вендора minibb.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 11
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
18 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2006-7156Proof of concept | PHP remote file inclusion vulnerability in addon_keywords.php in Keyword Replacer (keyword_replacer) 1.0 and earlier, a module for miniBB, aminibb · keyword replacer | Критическая10,0 | — | 4,8 % | 7 мар. 2007 г. |
41В плане | CVE-2006-7153Эксплойта нет | PHP remote file inclusion vulnerability in index.php in MiniBB Forum 2 allows remote attackers to execute arbitrary code via a URL in the paminibb · forum | Критическая10,0 | — | 3,8 % | 7 мар. 2007 г. |
33Наблюдать | CVE-2006-3955Proof of concept | Multiple PHP remote file inclusion vulnerabilities in MiniBB Forum 1.5a allow remote attackers to execute arbitrary PHP code via a URL in thminibb · minibb | Высокая7,5 | — | 9,8 % | 1 авг. 2006 г. |
32Наблюдать | CVE-2007-2317Proof of concept | Multiple PHP remote file inclusion vulnerabilities in MiniBB Forum 1.5a and earlier, as used by TOSMO/Mambo 4.0.12 and probably other producminibb · minibb | Высокая7,5 | — | 8,0 % | 26 апр. 2007 г. |
32Наблюдать | CVE-2007-3272Proof of concept | Directory traversal vulnerability in index.php in MiniBB 2.0.5 allows remote attackers to read arbitrary files via a ..minibb · minibb | Высокая7,8 | — | 2,8 % | 19 июн. 2007 г. |
31Наблюдать | CVE-2006-3690Proof of concept | Multiple PHP remote file inclusion vulnerabilities in MiniBB Forum 1.5a and earlier allow remote attackers to execute arbitrary PHP code viaminibb · forum | Высокая7,5 | — | 3,8 % | 21 июл. 2006 г. |
31Наблюдать | CVE-2004-2456Proof of concept | SQL injection vulnerability in index.php in miniBB 1.7f and earlier allows remote attackers to execute arbitrary SQL commands via the user pminibb · minibb | Высокая7,5 | — | 2,7 % | 31 дек. 2004 г. |
30Наблюдать | CVE-2008-2067Эксплойта нет | SQL injection vulnerability in bb_admin.php in miniBB 2.2a allows remote attackers to execute arbitrary SQL commands via the whatus parameteminibb · minibb · CWE-89 | Высокая7,5 | — | 1,6 % | 2 мая 2008 г. |
30Наблюдать | CVE-2006-5674Эксплойта нет | Multiple PHP remote file inclusion vulnerabilities in miniBB 2.0.2 and earlier, when register_globals is enabled, allow remote attackers to minibb · minibb | Высокая7,5 | — | 1,4 % | 2 нояб. 2006 г. |
30Наблюдать | CVE-2014-9254Proof of concept | bb_func_unsub.php in MiniBB 3.1 before 20141127 uses an incorrect regular expression, which allows remote attackers to conduct SQl injectionminibb · minibb · CWE-89 | Высокая7,5 | — | 1,3 % | 31 дек. 2014 г. |
30Наблюдать | CVE-2007-5719Proof of concept | SQL injection vulnerability in bb_func_search.php in miniBB 2.1 allows remote attackers to execute arbitrary SQL commands via the table paraminibb · minibb · CWE-89 | Высокая7,5 | — | 1,0 % | 30 окт. 2007 г. |
29Наблюдать | CVE-2006-5673Proof of concept | PHP remote file inclusion vulnerability in bb_func_txt.php in miniBB 2.0.2 and earlier, when register_globals is enabled, allows remote attaminibb · minibb | Средняя6,8 | — | 6,1 % | 2 нояб. 2006 г. |
27Наблюдать | CVE-2008-2029Proof of concept | Multiple SQL injection vulnerabilities in (1) setup_mysql.php and (2) setup_options.php in miniBB 2.2 and possibly earlier, when register_glminibb · minibb · CWE-89 | Средняя6,8 | — | 1,0 % | 30 апр. 2008 г. |
19Наблюдать | CVE-2018-6506Эксплойта нет | Cross-Site Scripting (XSS) exists in the Add Forum feature in the Administrative Panel in miniBB 3.2.2 via crafted use of an onload attributminibb · minibb · CWE-79 | Средняя4,8 | — | 0,5 % | 12 февр. 2018 г. |
18Наблюдать | CVE-2008-2028Proof of concept | miniBB 2.2, and possibly earlier, when register_globals is enabled, allows remote attackers to obtain the full path via a direct request to minibb · minibb · CWE-200 | Средняя4,3 | — | 2,2 % | 30 апр. 2008 г. |
18Наблюдать | CVE-2013-5020Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in bb_admin.php in MiniBB before 3.0.1 allow remote attackers to inject arbitrary web scminibb · minibb · CWE-79 | Средняя4,3 | — | 1,9 % | 31 июл. 2013 г. |
17Наблюдать | CVE-2008-2066Эксплойта нет | Cross-site scripting (XSS) vulnerability in bb_admin.php in miniBB 2.2a allows remote attackers to inject arbitrary web script or HTML via tminibb · minibb · CWE-79 | Средняя4,3 | — | 1,6 % | 2 мая 2008 г. |
17Наблюдать | CVE-2008-2024Proof of concept | Cross-site scripting (XSS) vulnerability in index.php in miniBB 2.2, and possibly earlier, when register_globals is enabled, allows remote aminibb · minibb · CWE-79 | Средняя4,3 | — | 1,5 % | 30 апр. 2008 г. |
- CVE-2006-715641В плане
PHP remote file inclusion vulnerability in addon_keywords.php in Keyword Replacer (keyword_replacer) 1.0 and earlier, a module for miniBB, a
КритическаяCVSS 10,0Proof of conceptEPSS 5 %minibb · keyword replacer7 мар. 2007 г.
- CVE-2006-715341В плане
PHP remote file inclusion vulnerability in index.php in MiniBB Forum 2 allows remote attackers to execute arbitrary code via a URL in the pa
КритическаяCVSS 10,0Эксплойта нетEPSS 4 %minibb · forum7 мар. 2007 г.
- CVE-2006-395533Наблюдать
Multiple PHP remote file inclusion vulnerabilities in MiniBB Forum 1.5a allow remote attackers to execute arbitrary PHP code via a URL in th
ВысокаяCVSS 7,5Proof of conceptEPSS 10 %minibb · minibb1 авг. 2006 г.
- CVE-2007-231732Наблюдать
Multiple PHP remote file inclusion vulnerabilities in MiniBB Forum 1.5a and earlier, as used by TOSMO/Mambo 4.0.12 and probably other produc
ВысокаяCVSS 7,5Proof of conceptEPSS 8 %minibb · minibb26 апр. 2007 г.
- CVE-2007-327232Наблюдать
Directory traversal vulnerability in index.php in MiniBB 2.0.5 allows remote attackers to read arbitrary files via a ..
ВысокаяCVSS 7,8Proof of conceptEPSS 3 %minibb · minibb19 июн. 2007 г.
- CVE-2006-369031Наблюдать
Multiple PHP remote file inclusion vulnerabilities in MiniBB Forum 1.5a and earlier allow remote attackers to execute arbitrary PHP code via
ВысокаяCVSS 7,5Proof of conceptEPSS 4 %minibb · forum21 июл. 2006 г.
- CVE-2004-245631Наблюдать
SQL injection vulnerability in index.php in miniBB 1.7f and earlier allows remote attackers to execute arbitrary SQL commands via the user p
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %minibb · minibb31 дек. 2004 г.
- CVE-2008-206730Наблюдать
SQL injection vulnerability in bb_admin.php in miniBB 2.2a allows remote attackers to execute arbitrary SQL commands via the whatus paramete
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %minibb · minibb2 мая 2008 г.
- CVE-2006-567430Наблюдать
Multiple PHP remote file inclusion vulnerabilities in miniBB 2.0.2 and earlier, when register_globals is enabled, allow remote attackers to
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %minibb · minibb2 нояб. 2006 г.
- CVE-2014-925430Наблюдать
bb_func_unsub.php in MiniBB 3.1 before 20141127 uses an incorrect regular expression, which allows remote attackers to conduct SQl injection
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %minibb · minibb31 дек. 2014 г.
- CVE-2007-571930Наблюдать
SQL injection vulnerability in bb_func_search.php in miniBB 2.1 allows remote attackers to execute arbitrary SQL commands via the table para
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %minibb · minibb30 окт. 2007 г.
- CVE-2006-567329Наблюдать
PHP remote file inclusion vulnerability in bb_func_txt.php in miniBB 2.0.2 and earlier, when register_globals is enabled, allows remote atta
СредняяCVSS 6,8Proof of conceptEPSS 6 %minibb · minibb2 нояб. 2006 г.
- CVE-2008-202927Наблюдать
Multiple SQL injection vulnerabilities in (1) setup_mysql.php and (2) setup_options.php in miniBB 2.2 and possibly earlier, when register_gl
СредняяCVSS 6,8Proof of conceptEPSS 1 %minibb · minibb30 апр. 2008 г.
- CVE-2018-650619Наблюдать
Cross-Site Scripting (XSS) exists in the Add Forum feature in the Administrative Panel in miniBB 3.2.2 via crafted use of an onload attribut
СредняяCVSS 4,8Эксплойта нетEPSS 1 %minibb · minibb12 февр. 2018 г.
- CVE-2008-202818Наблюдать
miniBB 2.2, and possibly earlier, when register_globals is enabled, allows remote attackers to obtain the full path via a direct request to
СредняяCVSS 4,3Proof of conceptEPSS 2 %minibb · minibb30 апр. 2008 г.
- CVE-2013-502018Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in bb_admin.php in MiniBB before 3.0.1 allow remote attackers to inject arbitrary web sc
СредняяCVSS 4,3Proof of conceptEPSS 2 %minibb · minibb31 июл. 2013 г.
- CVE-2008-206617Наблюдать
Cross-site scripting (XSS) vulnerability in bb_admin.php in miniBB 2.2a allows remote attackers to inject arbitrary web script or HTML via t
СредняяCVSS 4,3Эксплойта нетEPSS 2 %minibb · minibb2 мая 2008 г.
- CVE-2008-202417Наблюдать
Cross-site scripting (XSS) vulnerability in index.php in miniBB 2.2, and possibly earlier, when register_globals is enabled, allows remote a
СредняяCVSS 4,3Proof of conceptEPSS 2 %minibb · minibb30 апр. 2008 г.