Vulnerabilities > Woltlab

DATE CVE VULNERABILITY TITLE RISK
2006-09-27 CVE-2006-5029 SQL-Injection vulnerability in Burning Board
SQL injection vulnerability in thread.php in WoltLab Burning Board (wBB) 2.3.x allows remote attackers to obtain the version numbers of PHP, MySQL, and wBB via the page parameter.
network
low complexity
woltlab
7.5
2006-08-24 CVE-2006-4317 HTML Injection vulnerability in Woltlab Burning Board 2.3.5
Cross-site scripting (XSS) vulnerability in attachment.php in WoltLab Burning Board (WBB) 2.3.5 allows remote attackers to inject arbitrary web script or HTML via a GIF image that contains URL-encoded Javascript.
network
woltlab
6.8
2006-06-28 CVE-2006-3256 SQL Injection vulnerability in Woltlab Burning Board 2.3.1
SQL injection vulnerability in report.php in Woltlab Burning Board (WBB) 2.3.1 allows remote attackers to execute arbitrary SQL commands via the postid parameter.
network
low complexity
woltlab
7.5
2006-06-28 CVE-2006-3255 SQL Injection vulnerability in Woltlab Burning Board 1.2
SQL injection vulnerability in showmods.php in Woltlab Burning Board (WBB) 1.2 allows remote attackers to execute arbitrary SQL commands via the boardid parameter.
network
low complexity
woltlab
7.5
2006-06-28 CVE-2006-3254 SQL Injection vulnerability in Woltlab Burning Board 2.0Rc2
SQL injection vulnerability in newthread.php in Woltlab Burning Board (WBB) 2.0 RC2 allows remote attackers to execute arbitrary SQL commands via the boardid parameter.
network
low complexity
woltlab
7.5
2006-06-24 CVE-2006-3220 SQL-Injection vulnerability in Woltlab Burning Board 2.2.1
SQL injection vulnerability in studienplatztausch.php in Woltlab Burning Board (WBB) 2.2.1 allows remote attackers to execute arbitrary SQL commands via the sid parameter.
network
low complexity
woltlab
7.5
2006-06-24 CVE-2006-3219 SQL-Injection vulnerability in Woltlab Burning Board 2.2.2
SQL injection vulnerability in thread.php in Woltlab Burning Board (WBB) 2.2.2 allows remote attackers to execute arbitrary SQL commands via the threadid parameter.
network
low complexity
woltlab
7.5
2006-06-24 CVE-2006-3218 SQL-Injection vulnerability in Woltlab Burning Board 2.1.6
SQL injection vulnerability in profile.php in Woltlab Burning Board (WBB) 2.1.6 allows remote attackers to execute arbitrary SQL commands via the userid parameter.
network
low complexity
woltlab
7.5
2006-06-03 CVE-2006-2792 SQL-Injection vulnerability in Woltlab Burning Board 2.3.4
SQL injection vulnerability in misc.php in Woltlab Burning Board (WBB) 2.3.4 allows remote attackers to execute arbitrary SQL commands via the sid parameter.
network
low complexity
woltlab
7.5
2006-05-24 CVE-2006-2569 SQL Injection vulnerability in Woltlab Burning Board Links.PHP
SQL injection vulnerability in links.php in 4R Linklist 1.0 RC2 and earlier, a module for Woltlab Burning Board, allows remote attackers to execute arbitrary SQL commands via the cat parameter.
network
low complexity
4r-linklist woltlab
7.5