Vulnerabilities > Phpbb Group > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2004-12-23 | CVE-2004-2130 | Cross-Site Scripting vulnerability in PHPbb Group PHPbb 2.0.6 Multiple cross-site scripting (XSS) vulnerabilities in privmsg.php in phpBB 2.0.6 allow remote attackers to execute arbitrary script or HTML via the (1) folder or (2) mode variables. network phpbb-group | 4.3 |
2004-11-23 | CVE-2004-0339 | Cross-Site Scripting vulnerability in PHPBB Cross-site scripting (XSS) vulnerability in ViewTopic.php in phpBB, possibly 2.0.6c and earlier, allows remote attackers to execute arbitrary script or HTML as other users via the postorder parameter. network phpbb-group | 6.8 |
2004-07-27 | CVE-2004-0730 | Cross-Site Scripting vulnerability in PHPbb 2.0.8/2.0.8A Multiple cross-site scripting (XSS) vulnerabilities in PhpBB 2.0.8 allow remote attackers to inject arbitrary web script or HTML via (1) the cat_title parameter in index.php, (2) the faq[0][0] parameter in lang_faq.php as accessible from faq.php, or (3) the faq[0][0] parameter in lang_bbcode.php as accessible from faq.php. network phpbb-group | 6.8 |
2004-07-27 | CVE-2004-0729 | Information Disclosure vulnerability in PHPbb 2.0.8/2.0.8A PhpBB 2.0.8 allows remote attackers to gain sensitive information via an invalid (1) category_rows parameter to index.php, (2) faq parameter to faq.php, or (3) ranksrow parameter to profile.php, which reveal the full path in an error message. | 5.0 |
2004-07-19 | CVE-2004-2055 | HTTP Response Splitting vulnerability in PHPBB Cross-site scripting (XSS) vulnerability in search.php for PhpBB 2.0.4 and 2.0.9 allows remote attackers to inject arbitrary HTMl or web script via the search_author parameter. network phpbb-group | 4.3 |
2004-04-19 | CVE-2004-1950 | Unspecified vulnerability in PHPbb Group PHPbb phpBB 2.0.8a and earlier trusts the IP address that is in the X-Forwarded-For in the HTTP header, which allows remote attackers to spoof IP addresses. | 5.0 |
2003-12-31 | CVE-2003-1373 | Path Traversal vulnerability in PHPbb Group PHPbb Directory traversal vulnerability in auth.php for PhpBB 1.4.0 through 1.4.4 allows remote attackers to read and include arbitrary files via .. | 6.8 |
2003-12-29 | CVE-2003-1215 | SQL Injection vulnerability in phpBB GroupCP.PHP SQL injection vulnerability in groupcp.php for phpBB 2.0.6 and earlier allows group moderators to perform unauthorized activities via the sql_in parameter. | 4.6 |
2003-08-07 | CVE-2003-0486 | SQL Injection vulnerability in phpBB Viewtopic.PHP SQL injection vulnerability in viewtopic.php for phpBB 2.0.5 and earlier allows remote attackers to steal password hashes via the topic_id parameter. | 5.0 |
2003-08-07 | CVE-2003-0484 | Cross-Site Scripting vulnerability in phpBB Cross-site scripting (XSS) vulnerability in viewtopic.php for phpBB allows remote attackers to insert arbitrary web script via the topic_id parameter. network phpbb-group | 6.8 |