UseBB kayıtları
usebb üreticisine ait 12 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-20 Improper Input Validation1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-352 Cross-Site Request Forgery (CSRF)1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
12 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2020-8088İstismar yok | panel_login.php in UseBB 1.0.12 allows type juggling for login bypass because != is used instead of !== for password hashes, which mishandleusebb · usebb | Kritik9,8 | — | %1,4 | 27 Oca 2020 |
38İzleyin | CVE-2007-3963Kavram kanıtı | Multiple cross-site scripting (XSS) vulnerabilities in UseBB 1.0.7, and possibly other 1.0.x versions, allow remote attackers to inject arbiusebb · usebb | Kritik9,3 | — | %2,4 | 25 Tem 2007 |
35İzleyin | CVE-2011-3612İstismar yok | Cross-Site Request Forgery (CSRF) vulnerability exists in panel.php in UseBB before 1.0.12.usebb · usebb · CWE-352 | Yüksek8,8 | — | %0,9 | 22 Oca 2020 |
30İzleyin | CVE-2005-2439İstismar yok | SQL injection vulnerability in UseBB 0.5.1 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL usebb · usebb | Yüksek7,5 | — | %1,2 | 3 Ağu 2005 |
29İzleyin | CVE-2011-3611İstismar yok | A File Inclusion vulnerability exists in act parameter to admin.php in UseBB before 1.0.12.usebb · usebb · CWE-20 | Yüksek7,2 | — | %2,6 | 22 Oca 2020 |
27İzleyin | CVE-2006-2524İstismar yok | Cross-site scripting (XSS) vulnerability in UseBB 1.0 RC1 and earlier allows remote attackers to inject arbitrary web script or HTML via unsusebb · usebb | Orta6,8 | — | %1,4 | 22 May 2006 |
25İzleyin | CVE-2006-2525İstismar yok | SQL injection vulnerability in UseBB 1.0 RC1 and earlier allows remote attackers to execute arbitrary SQL commands via the member list searcusebb · usebb | Orta6,4 | — | %1,3 | 22 May 2006 |
21İzleyin | CVE-2009-4041İstismar yok | UseBB 1.0.9 before 1.0.10 allows remote attackers to cause a denial of service (infinite loop) via crafted BBCode tags.usebb · usebb | Orta5,0 | — | %2,2 | 20 Kas 2009 |
20İzleyin | CVE-2007-2066İstismar yok | UseBB before 1.0.6 allows remote attackers to obtain sensitive information via a request with unspecified GET or POST parameters to an unspeusebb · usebb | Orta5,0 | — | %1,2 | 17 Nis 2007 |
17İzleyin | CVE-2005-2438İstismar yok | Cross-site scripting (XSS) vulnerability in UseBB 0.5.1 and earlier allows remote attackers to inject arbitrary Javascript via the BBCode cousebb · usebb | Orta4,3 | — | %1,2 | 3 Ağu 2005 |
17İzleyin | CVE-2005-4193İstismar yok | Cross-site scripting (XSS) vulnerability in UseBB before 0.7 allows remote attackers to inject arbitrary web script or HTML via the $_SERVERusebb · usebb | Orta4,3 | — | %1,2 | 13 Ara 2005 |
17İzleyin | CVE-2010-3713İstismar yok | rss.php in UseBB before 1.0.11 does not properly handle forum configurations in which a user has the view permission but not the read permisusebb · usebb · CWE-264 | Orta4,3 | — | %1,2 | 27 Eki 2010 |
- CVE-2020-808839İzleyin
panel_login.php in UseBB 1.0.12 allows type juggling for login bypass because != is used instead of !== for password hashes, which mishandle
KritikCVSS 9,8İstismar yokEPSS %1usebb · usebb27 Oca 2020
- CVE-2007-396338İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in UseBB 1.0.7, and possibly other 1.0.x versions, allow remote attackers to inject arbi
KritikCVSS 9,3Kavram kanıtıEPSS %2usebb · usebb25 Tem 2007
- CVE-2011-361235İzleyin
Cross-Site Request Forgery (CSRF) vulnerability exists in panel.php in UseBB before 1.0.12.
YüksekCVSS 8,8İstismar yokEPSS %1usebb · usebb22 Oca 2020
- CVE-2005-243930İzleyin
SQL injection vulnerability in UseBB 0.5.1 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL
YüksekCVSS 7,5İstismar yokEPSS %1usebb · usebb3 Ağu 2005
- CVE-2011-361129İzleyin
A File Inclusion vulnerability exists in act parameter to admin.php in UseBB before 1.0.12.
YüksekCVSS 7,2İstismar yokEPSS %3usebb · usebb22 Oca 2020
- CVE-2006-252427İzleyin
Cross-site scripting (XSS) vulnerability in UseBB 1.0 RC1 and earlier allows remote attackers to inject arbitrary web script or HTML via uns
OrtaCVSS 6,8İstismar yokEPSS %1usebb · usebb22 May 2006
- CVE-2006-252525İzleyin
SQL injection vulnerability in UseBB 1.0 RC1 and earlier allows remote attackers to execute arbitrary SQL commands via the member list searc
OrtaCVSS 6,4İstismar yokEPSS %1usebb · usebb22 May 2006
- CVE-2009-404121İzleyin
UseBB 1.0.9 before 1.0.10 allows remote attackers to cause a denial of service (infinite loop) via crafted BBCode tags.
OrtaCVSS 5,0İstismar yokEPSS %2usebb · usebb20 Kas 2009
- CVE-2007-206620İzleyin
UseBB before 1.0.6 allows remote attackers to obtain sensitive information via a request with unspecified GET or POST parameters to an unspe
OrtaCVSS 5,0İstismar yokEPSS %1usebb · usebb17 Nis 2007
- CVE-2005-243817İzleyin
Cross-site scripting (XSS) vulnerability in UseBB 0.5.1 and earlier allows remote attackers to inject arbitrary Javascript via the BBCode co
OrtaCVSS 4,3İstismar yokEPSS %1usebb · usebb3 Ağu 2005
- CVE-2005-419317İzleyin
Cross-site scripting (XSS) vulnerability in UseBB before 0.7 allows remote attackers to inject arbitrary web script or HTML via the $_SERVER
OrtaCVSS 4,3İstismar yokEPSS %1usebb · usebb13 Ara 2005
- CVE-2010-371317İzleyin
rss.php in UseBB before 1.0.11 does not properly handle forum configurations in which a user has the view permission but not the read permis
OrtaCVSS 4,3İstismar yokEPSS %1usebb · usebb27 Eki 2010