Перейти к содержимому
Noroxi

Записи UseBB

12 опубликованных записей вендора usebb.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
2
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Записи по годам

  1. 20

Столбик: всего · тёмная часть: CISA KEV.

Повторяющиеся классы

Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.

CWE

Все записи

12 записей
  • CVE-2020-8088
    39Наблюдать

    panel_login.php in UseBB 1.0.12 allows type juggling for login bypass because != is used instead of !== for password hashes, which mishandle

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    usebb · usebb27 янв. 2020 г.

  • CVE-2007-3963
    38Наблюдать

    Multiple cross-site scripting (XSS) vulnerabilities in UseBB 1.0.7, and possibly other 1.0.x versions, allow remote attackers to inject arbi

    КритическаяCVSS 9,3Proof of conceptEPSS 2 %

    usebb · usebb25 июл. 2007 г.

  • CVE-2011-3612
    35Наблюдать

    Cross-Site Request Forgery (CSRF) vulnerability exists in panel.php in UseBB before 1.0.12.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    usebb · usebb22 янв. 2020 г.

  • CVE-2005-2439
    30Наблюдать

    SQL injection vulnerability in UseBB 0.5.1 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    usebb · usebb3 авг. 2005 г.

  • CVE-2011-3611
    29Наблюдать

    A File Inclusion vulnerability exists in act parameter to admin.php in UseBB before 1.0.12.

    ВысокаяCVSS 7,2Эксплойта нетEPSS 3 %

    usebb · usebb22 янв. 2020 г.

  • CVE-2006-2524
    27Наблюдать

    Cross-site scripting (XSS) vulnerability in UseBB 1.0 RC1 and earlier allows remote attackers to inject arbitrary web script or HTML via uns

    СредняяCVSS 6,8Эксплойта нетEPSS 1 %

    usebb · usebb22 мая 2006 г.

  • CVE-2006-2525
    25Наблюдать

    SQL injection vulnerability in UseBB 1.0 RC1 and earlier allows remote attackers to execute arbitrary SQL commands via the member list searc

    СредняяCVSS 6,4Эксплойта нетEPSS 1 %

    usebb · usebb22 мая 2006 г.

  • CVE-2009-4041
    21Наблюдать

    UseBB 1.0.9 before 1.0.10 allows remote attackers to cause a denial of service (infinite loop) via crafted BBCode tags.

    СредняяCVSS 5,0Эксплойта нетEPSS 2 %

    usebb · usebb20 нояб. 2009 г.

  • CVE-2007-2066
    20Наблюдать

    UseBB before 1.0.6 allows remote attackers to obtain sensitive information via a request with unspecified GET or POST parameters to an unspe

    СредняяCVSS 5,0Эксплойта нетEPSS 1 %

    usebb · usebb17 апр. 2007 г.

  • CVE-2005-2438
    17Наблюдать

    Cross-site scripting (XSS) vulnerability in UseBB 0.5.1 and earlier allows remote attackers to inject arbitrary Javascript via the BBCode co

    СредняяCVSS 4,3Эксплойта нетEPSS 1 %

    usebb · usebb3 авг. 2005 г.

  • CVE-2005-4193
    17Наблюдать

    Cross-site scripting (XSS) vulnerability in UseBB before 0.7 allows remote attackers to inject arbitrary web script or HTML via the $_SERVER

    СредняяCVSS 4,3Эксплойта нетEPSS 1 %

    usebb · usebb13 дек. 2005 г.

  • CVE-2010-3713
    17Наблюдать

    rss.php in UseBB before 1.0.11 does not properly handle forum configurations in which a user has the view permission but not the read permis

    СредняяCVSS 4,3Эксплойта нетEPSS 1 %

    usebb · usebb27 окт. 2010 г.