Записи UseBB
12 опубликованных записей вендора usebb.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-20 Improper Input Validation1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-352 Cross-Site Request Forgery (CSRF)1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
12 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2020-8088Эксплойта нет | panel_login.php in UseBB 1.0.12 allows type juggling for login bypass because != is used instead of !== for password hashes, which mishandleusebb · usebb | Критическая9,8 | — | 1,4 % | 27 янв. 2020 г. |
38Наблюдать | CVE-2007-3963Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in UseBB 1.0.7, and possibly other 1.0.x versions, allow remote attackers to inject arbiusebb · usebb | Критическая9,3 | — | 2,4 % | 25 июл. 2007 г. |
35Наблюдать | CVE-2011-3612Эксплойта нет | Cross-Site Request Forgery (CSRF) vulnerability exists in panel.php in UseBB before 1.0.12.usebb · usebb · CWE-352 | Высокая8,8 | — | 0,9 % | 22 янв. 2020 г. |
30Наблюдать | CVE-2005-2439Эксплойта нет | SQL injection vulnerability in UseBB 0.5.1 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL usebb · usebb | Высокая7,5 | — | 1,2 % | 3 авг. 2005 г. |
29Наблюдать | CVE-2011-3611Эксплойта нет | A File Inclusion vulnerability exists in act parameter to admin.php in UseBB before 1.0.12.usebb · usebb · CWE-20 | Высокая7,2 | — | 2,6 % | 22 янв. 2020 г. |
27Наблюдать | CVE-2006-2524Эксплойта нет | Cross-site scripting (XSS) vulnerability in UseBB 1.0 RC1 and earlier allows remote attackers to inject arbitrary web script or HTML via unsusebb · usebb | Средняя6,8 | — | 1,4 % | 22 мая 2006 г. |
25Наблюдать | CVE-2006-2525Эксплойта нет | SQL injection vulnerability in UseBB 1.0 RC1 and earlier allows remote attackers to execute arbitrary SQL commands via the member list searcusebb · usebb | Средняя6,4 | — | 1,3 % | 22 мая 2006 г. |
21Наблюдать | CVE-2009-4041Эксплойта нет | UseBB 1.0.9 before 1.0.10 allows remote attackers to cause a denial of service (infinite loop) via crafted BBCode tags.usebb · usebb | Средняя5,0 | — | 2,2 % | 20 нояб. 2009 г. |
20Наблюдать | CVE-2007-2066Эксплойта нет | UseBB before 1.0.6 allows remote attackers to obtain sensitive information via a request with unspecified GET or POST parameters to an unspeusebb · usebb | Средняя5,0 | — | 1,2 % | 17 апр. 2007 г. |
17Наблюдать | CVE-2005-2438Эксплойта нет | Cross-site scripting (XSS) vulnerability in UseBB 0.5.1 and earlier allows remote attackers to inject arbitrary Javascript via the BBCode cousebb · usebb | Средняя4,3 | — | 1,2 % | 3 авг. 2005 г. |
17Наблюдать | CVE-2005-4193Эксплойта нет | Cross-site scripting (XSS) vulnerability in UseBB before 0.7 allows remote attackers to inject arbitrary web script or HTML via the $_SERVERusebb · usebb | Средняя4,3 | — | 1,2 % | 13 дек. 2005 г. |
17Наблюдать | CVE-2010-3713Эксплойта нет | rss.php in UseBB before 1.0.11 does not properly handle forum configurations in which a user has the view permission but not the read permisusebb · usebb · CWE-264 | Средняя4,3 | — | 1,2 % | 27 окт. 2010 г. |
- CVE-2020-808839Наблюдать
panel_login.php in UseBB 1.0.12 allows type juggling for login bypass because != is used instead of !== for password hashes, which mishandle
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %usebb · usebb27 янв. 2020 г.
- CVE-2007-396338Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in UseBB 1.0.7, and possibly other 1.0.x versions, allow remote attackers to inject arbi
КритическаяCVSS 9,3Proof of conceptEPSS 2 %usebb · usebb25 июл. 2007 г.
- CVE-2011-361235Наблюдать
Cross-Site Request Forgery (CSRF) vulnerability exists in panel.php in UseBB before 1.0.12.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %usebb · usebb22 янв. 2020 г.
- CVE-2005-243930Наблюдать
SQL injection vulnerability in UseBB 0.5.1 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %usebb · usebb3 авг. 2005 г.
- CVE-2011-361129Наблюдать
A File Inclusion vulnerability exists in act parameter to admin.php in UseBB before 1.0.12.
ВысокаяCVSS 7,2Эксплойта нетEPSS 3 %usebb · usebb22 янв. 2020 г.
- CVE-2006-252427Наблюдать
Cross-site scripting (XSS) vulnerability in UseBB 1.0 RC1 and earlier allows remote attackers to inject arbitrary web script or HTML via uns
СредняяCVSS 6,8Эксплойта нетEPSS 1 %usebb · usebb22 мая 2006 г.
- CVE-2006-252525Наблюдать
SQL injection vulnerability in UseBB 1.0 RC1 and earlier allows remote attackers to execute arbitrary SQL commands via the member list searc
СредняяCVSS 6,4Эксплойта нетEPSS 1 %usebb · usebb22 мая 2006 г.
- CVE-2009-404121Наблюдать
UseBB 1.0.9 before 1.0.10 allows remote attackers to cause a denial of service (infinite loop) via crafted BBCode tags.
СредняяCVSS 5,0Эксплойта нетEPSS 2 %usebb · usebb20 нояб. 2009 г.
- CVE-2007-206620Наблюдать
UseBB before 1.0.6 allows remote attackers to obtain sensitive information via a request with unspecified GET or POST parameters to an unspe
СредняяCVSS 5,0Эксплойта нетEPSS 1 %usebb · usebb17 апр. 2007 г.
- CVE-2005-243817Наблюдать
Cross-site scripting (XSS) vulnerability in UseBB 0.5.1 and earlier allows remote attackers to inject arbitrary Javascript via the BBCode co
СредняяCVSS 4,3Эксплойта нетEPSS 1 %usebb · usebb3 авг. 2005 г.
- CVE-2005-419317Наблюдать
Cross-site scripting (XSS) vulnerability in UseBB before 0.7 allows remote attackers to inject arbitrary web script or HTML via the $_SERVER
СредняяCVSS 4,3Эксплойта нетEPSS 1 %usebb · usebb13 дек. 2005 г.
- CVE-2010-371317Наблюдать
rss.php in UseBB before 1.0.11 does not properly handle forum configurations in which a user has the view permission but not the read permis
СредняяCVSS 4,3Эксплойта нетEPSS 1 %usebb · usebb27 окт. 2010 г.