Filters

Phpbb Group PhpbbInput Validation

First published (updated )

Phpbb Group PhpbbCSRF

First published (updated )

Phpbb Group PhpbbXSS

First published (updated )

Phpbb Group PhpbbphpBB 2.0.21 does not properly handle pathnames ending in %00, which allows remote authenticated adm…

First published (updated )

Phpbb Group Phpbbusercp_avatar.php in PHPBB 2.0.20, when avatar uploading is enabled, allows remote attackers to use …

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Phpbb Group PhpbbXSS, SQL Injection

First published (updated )

Phpbb Group PhpbbPHP remote file inclusion vulnerability in /includes/kb_constants.php in Knowledge Base Mod for PHPb…

First published (updated )

Phpbb Group PhpbbCode Injection

First published (updated )

Phpbb Group PhpbbCode Injection

First published (updated )

Phpbb Group PhpbbXSS

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Phpbb Group PhpbbXSS

First published (updated )

Phpbb Group PhpbbThe gen_rand_string function in phpBB 2.0.19 uses insufficiently random data (small value space) to …

First published (updated )

Phpbb Group PhpbbCSRF

First published (updated )

Phpbb Group PhpbbXSS

First published (updated )

Phpbb Group PhpbbphpBB 2.0.19 and earlier allows remote attackers to cause a denial of service (application crash) by…

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Phpbb Group PhpbbXSS

First published (updated )

Phpbb Group PhpbbA "missing request validation" error in phpBB 2 before 2.0.18 allows remote attackers to edit privat…

First published (updated )

Phpbb Group Phpbbadmin/admin_disallow.php in phpBB 2.0.18 allows remote attackers to obtain the installation path via…

First published (updated )

Phpbb Group PhpbbphpBB 2.0.18 allows remote attackers to obtain sensitive information via a large SQL query, which ge…

First published (updated )

Phpbb Group PhpbbXSS

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Phpbb Group PhpbbXSS

First published (updated )

Phpbb Group PhpbbXSS

First published (updated )

Phpbb Group PhpbbXSS

First published (updated )

Phpbb Group PhpbbXSS

First published (updated )

Phpbb Group PhpbbXSS

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Phpbb Group Phpbbcalendar_scheduler.php in Topic Calendar 1.0.1 module for phpBB, when running on a Microsoft IIS ser…

First published (updated )

Phpbb Group PhpbbXSS

First published (updated )

Phpbb Group PhpbbphpBB 2.0.13 and earlier allows remote attackers to obtain sensitive information via a direct reques…

First published (updated )

Phpbb Group Phpbbviewtopic.php in phpBB 2.0.12 and earlier allows remote attackers to obtain sensitive information vi…

First published (updated )

Phpbb Group PhpbbphpBB 2.0.11, and possibly other versions, with remote avatars and avatar uploading enabled, allows …

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Phpbb Group PhpbbDirectory traversal vulnerability in (1) usercp_register.php and (2) usercp_avatar.php for phpBB 2.0…

First published (updated )

Phpbb Group PhpbbXSS

First published (updated )

Phpbb Group PhpbbXSS

First published (updated )

Phpbb Group PhpbbCRLF Injection

First published (updated )

Phpbb Group PhpbbXSS

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Phpbb Group PhpbbXSS

First published (updated )

Phpbb Group PhpbbPhpBB 2.0.8 allows remote attackers to gain sensitive information via an invalid (1) category_rows p…

First published (updated )

Phpbb Group PhpbbXSS

First published (updated )

Phpbb Group PhpbbphpBB 2.0.8a and earlier trusts the IP address that is in the X-Forwarded-For in the HTTP header, wh…

First published (updated )

Phpbb Group PhpbbXSS

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Phpbb Group PhpbbPath Traversal

First published (updated )

Phpbb Group PhpbbSQL Injection

First published (updated )

Phpbb Group PhpbbSQL Injection

First published (updated )

Phpbb Group PhpbbXSS

First published (updated )

Phpbb Group Phpbbinstall.php in phpBB 2.0 through 2.0.1, when "allow_url_fopen" and "register_globals" variables are …

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Phpbb Group PhpbbXSS

First published (updated )

Phpbb Group PhpbbphpBB 1.4.4 and earlier with BBcode allows remote attackers to cause a denial of service (CPU consum…

First published (updated )

Phpbb Group PhpbbCross-site scripting vulnerability in phpBB 1.4.4 and earlier allows remote attackers to execute arb…

First published (updated )

Phpbb Group PhpbbSQL Injection

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203