SQL injection vulnerability in usergroups.php in Woltlab Burning Board (wBB) 2.x allows remote attackers to execute arbitrary SQL commands via the array index of the applicationids array.
SQL injection vulnerability in search.php in Woltlab Burning Board (wBB) 1.0.2 and earlier, and 2.3.6 and earlier in the 2.x series, allows remote attackers to execute arbitrary SQL commands via the boardids[1] and other boardids[] parameters.
Multiple cross-site scripting (XSS) vulnerabilities in register.php in Woltlab Burning Board (wBB) 2.3.6 and Burning Board Lite 1.0.2pl3e allow remote attackers to inject arbitrary web script or HTML via the (1) rusername, (2) remail, (3) rpassword, (4) rconfirmpassword, (5) rhomepage, (6) ricq, (7) raim, (8) ryim, (9) rmsn, (10) ryear, (11) rmonth, (12) rday, (13) rgender, (14) rsignature, (15) rusertext, (16) rinvisible, (17) rusecookies, (18) radmincanemail, (19) remailnotify, (20) rnotificationperpm, (21) rreceivepm, (22) remailonpm, (23) rpmpopup, (24) rshowsignatures, (25) rshowavatars, (26) rshowimages, (27) rdaysprune, (28) rumaxposts, (29) rdateformat, (30) rtimeformat, (31) rstartweek, (32) rtimezoneoffset, (33) rusewysiwyg, (34) rstyleid, (35) rlangid, (36) keystring, (37) keynumber, (38) disablesmilies, (39) disablebbcode, (40) disableimages, (41) field[1], (42) field[2], and (43) field[3] parameters. NOTE: a third-party researcher has disputed some of these vectors, stating that only the rdateformat and rtimeformat parameters in Burning Board 2.3.6 are affected.