Vulnerabilities > Usebb

DATE CVE VULNERABILITY TITLE RISK
2005-08-03 CVE-2005-2439 SQL Injection vulnerability in UseBB Search
SQL injection vulnerability in UseBB 0.5.1 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the search function.
network
low complexity
usebb
7.5
2005-08-03 CVE-2005-2438 Cross-site scripting (XSS) vulnerability in UseBB 0.5.1 and earlier allows remote attackers to inject arbitrary Javascript via the BBCode color value.
network
usebb
4.3