SQL injection vulnerability in pms.php in Woltlab Burning Board (wBB) Lite 1.0.2pl3e and earlier allows remote authenticated users to execute arbitrary SQL commands via the pmid[0] parameter.
Multiple SQL injection vulnerabilities in search.php in WoltLab Burning Board (wBB) Lite 1.0.2 pl3e allow remote attackers to execute arbitrary SQL commands via the (1) showposts, (2) sortby, and (3) sortorder parameters.
Multiple cross-site scripting (XSS) vulnerabilities in register.php in Woltlab Burning Board (wBB) 2.3.6 and Burning Board Lite 1.0.2pl3e allow remote attackers to inject arbitrary web script or HTML via the (1) rusername, (2) remail, (3) rpassword, (4) rconfirmpassword, (5) rhomepage, (6) ricq, (7) raim, (8) ryim, (9) rmsn, (10) ryear, (11) rmonth, (12) rday, (13) rgender, (14) rsignature, (15) rusertext, (16) rinvisible, (17) rusecookies, (18) radmincanemail, (19) remailnotify, (20) rnotificationperpm, (21) rreceivepm, (22) remailonpm, (23) rpmpopup, (24) rshowsignatures, (25) rshowavatars, (26) rshowimages, (27) rdaysprune, (28) rumaxposts, (29) rdateformat, (30) rtimeformat, (31) rstartweek, (32) rtimezoneoffset, (33) rusewysiwyg, (34) rstyleid, (35) rlangid, (36) keystring, (37) keynumber, (38) disablesmilies, (39) disablebbcode, (40) disableimages, (41) field[1], (42) field[2], and (43) field[3] parameters. NOTE: a third-party researcher has disputed some of these vectors, stating that only the rdateformat and rtimeformat parameters in Burning Board 2.3.6 are affected.