Vulnerabilities > Usebb > Usebb > 1.0.10

DATE CVE VULNERABILITY TITLE RISK
2020-01-22 CVE-2011-3612 Cross-Site Request Forgery (CSRF) vulnerability in Usebb
Cross-Site Request Forgery (CSRF) vulnerability exists in panel.php in UseBB before 1.0.12.
network
usebb CWE-352
6.8
2020-01-22 CVE-2011-3611 Improper Input Validation vulnerability in Usebb
A File Inclusion vulnerability exists in act parameter to admin.php in UseBB before 1.0.12.
network
low complexity
usebb CWE-20
critical
9.0
2010-10-28 CVE-2010-3713 Permissions, Privileges, and Access Controls vulnerability in Usebb
rss.php in UseBB before 1.0.11 does not properly handle forum configurations in which a user has the view permission but not the read permission, which allows remote attackers to bypass intended access restrictions by reading a forum feed in combination with a topic feed.
network
usebb CWE-264
4.3