Phpbb Group Phpbb vulnerabilities
75 known vulnerabilities affecting phpbb_group/phpbb.
Total CVEs
75
CISA KEV
0
Public exploits
20
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH22MEDIUM44LOW2
Vulnerabilities
Page 1 of 4
CVE-2007-1695CRITICALCVSS 10.0v2.0.192007-03-27
CVE-2007-1695 [CRITICAL] CVE-2007-1695: PHP remote file inclusion vulnerability in includes/usercp_register.php in phpBB 2.0.19 allows remot
PHP remote file inclusion vulnerability in includes/usercp_register.php in phpBB 2.0.19 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. NOTE: this issue has been disputed by third-party researchers, stating that the file checks for a global constant and cannot be accessed directly
nvd
CVE-2006-2219MEDIUMCVSS 5.0v2.0.202007-02-08
CVE-2006-2219 [MEDIUM] CWE-20 CVE-2006-2219: phpBB 2.0.20 does not verify user-specified input variable types before being passed to type-depende
phpBB 2.0.20 does not verify user-specified input variable types before being passed to type-dependent functions, which allows remote attackers to obtain sensitive information, as demonstrated by the (1) mode parameter to memberlist.php and the (2) highlight parameter to viewtopic.php that are used as an argument to the htmlspecialchars or urlencode fu
nvd
CVE-2006-6839CRITICALCVSS 10.0v1.2.4_rc3v2.0.18+2 more2006-12-31
CVE-2006-6839 [CRITICAL] CVE-2006-6839: Unspecified vulnerability in phpBB before 2.0.22 has unknown impact and remote attack vectors relate
Unspecified vulnerability in phpBB before 2.0.22 has unknown impact and remote attack vectors related to "criteria for 'bad' redirection targets."
nvd
CVE-2006-6840CRITICALCVSS 10.0v1.2.4_rc3v2.0.18+2 more2006-12-31
CVE-2006-6840 [CRITICAL] CVE-2006-6840: Unspecified vulnerability in phpBB before 2.0.22 has unknown impact and remote attack vectors relate
Unspecified vulnerability in phpBB before 2.0.22 has unknown impact and remote attack vectors related to a "negative start parameter."
nvd
CVE-2006-6841CRITICALCVSS 10.0v1.2.4_rc3v2.0.18+2 more2006-12-31
CVE-2006-6841 [CRITICAL] CVE-2006-6841: Certain forms in phpBB before 2.0.22 lack session checks, which has unknown impact and remote attack
Certain forms in phpBB before 2.0.22 lack session checks, which has unknown impact and remote attack vectors.
nvd
CVE-2006-6508MEDIUMCVSS 6.0v2.0.212006-12-14
CVE-2006-6508 [MEDIUM] CVE-2006-6508: Cross-site request forgery (CSRF) vulnerability in phpBB 2.0.21 allows remote authenticated users to
Cross-site request forgery (CSRF) vulnerability in phpBB 2.0.21 allows remote authenticated users to send unauthorized messages as an arbitrary user via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
nvd
CVE-2006-6421MEDIUMCVSS 6.0PoCv2.0v2.0.0+30 more2006-12-10
CVE-2006-6421 [MEDIUM] CVE-2006-6421: Cross-site scripting (XSS) vulnerability in the private message box implementation (privmsg.php) in
Cross-site scripting (XSS) vulnerability in the private message box implementation (privmsg.php) in phpBB 2.0.x allows remote authenticated users to inject arbitrary web script or HTML via the "Message body" field in a message to a non-existent user.
nvd
CVE-2006-5435HIGHCVSS 7.5≤ 2.0.102006-10-20
CVE-2006-5435 [HIGH] CVE-2006-5435: PHP remote file inclusion vulnerability in groupcp.php in phpBB 2.0.10 and earlier allows remote att
PHP remote file inclusion vulnerability in groupcp.php in phpBB 2.0.10 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. NOTE: CVE and the vendor dispute this vulnerability because $phpbb_root_path is defined before use
nvd
CVE-2006-5209HIGHCVSS 7.5PoCv2.0v2.0.1+29 more2006-10-10
CVE-2006-5209 [HIGH] CVE-2006-5209: PHP remote file inclusion vulnerability in admin/admin_topic_action_logging.php in Admin Topic Actio
PHP remote file inclusion vulnerability in admin/admin_topic_action_logging.php in Admin Topic Action Logging Mod 0.95 and earlier, as used in phpBB 2.0 up to 2.0.21, allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
nvd
CVE-2006-4758MEDIUMCVSS 4.6v2.0.212006-09-13
CVE-2006-4758 [MEDIUM] CVE-2006-4758: phpBB 2.0.21 does not properly handle pathnames ending in %00, which allows remote authenticated adm
phpBB 2.0.21 does not properly handle pathnames ending in %00, which allows remote authenticated administrative users to upload arbitrary files, as demonstrated by a query to admin/admin_board.php with an avatar_path parameter ending in .php%00.
nvd
CVE-2006-4450MEDIUMCVSS 5.1PoCv2.0.202006-08-30
CVE-2006-4450 [MEDIUM] CVE-2006-4450: usercp_avatar.php in PHPBB 2.0.20, when avatar uploading is enabled, allows remote attackers to use
usercp_avatar.php in PHPBB 2.0.20, when avatar uploading is enabled, allows remote attackers to use the server as a web proxy by submitting a URL to the avatarurl parameter, which is then used in an HTTP GET request.
nvd
CVE-2006-2865HIGHCVSS 7.5PoCv2.0v2.0.1+28 more2006-06-06
CVE-2006-2865 [HIGH] CVE-2006-2865: PHP remote file inclusion vulnerability in template.php in phpBB 2 allows remote attackers to execut
PHP remote file inclusion vulnerability in template.php in phpBB 2 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. NOTE: followup posts have disputed this issue, stating that template.php does not appear in phpBB and does not use a $page variable. It is possible that this is a site-specific vulnerability, or an issue in a
nvd
CVE-2006-2134MEDIUMCVSS 5.1PoC≤ 2.0.2v1.0.0+14 more2006-05-02
CVE-2006-2134 [MEDIUM] CVE-2006-2134: PHP remote file inclusion vulnerability in /includes/kb_constants.php in Knowledge Base Mod for PHPb
PHP remote file inclusion vulnerability in /includes/kb_constants.php in Knowledge Base Mod for PHPbb 2.0.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.
nvd
CVE-2006-1895MEDIUMCVSS 6.5v2.0.92006-04-20
CVE-2006-1895 [MEDIUM] CVE-2006-1895: Direct static code injection vulnerability in includes/template.php in phpBB allows remote authentic
Direct static code injection vulnerability in includes/template.php in phpBB allows remote authenticated users with write access to execute arbitrary PHP code by modifying a template in a way that (1) bypasses a loose ".*" regular expression to match BEGIN and END statements in overall_header.tpl, or (2) is used in an eval statement by includes/bbcode.php for
nvd
CVE-2006-1775MEDIUMCVSS 4.3v2.0.192006-04-13
CVE-2006-1775 [MEDIUM] CVE-2006-1775: Multiple cross-site scripting (XSS) vulnerabilities in phpBB 2.0.19 allow remote attackers to inject
Multiple cross-site scripting (XSS) vulnerabilities in phpBB 2.0.19 allow remote attackers to inject arbitrary web script or HTML via the (1) Site Description field in (a) admin_board.php, the (2) Group name and (3) Group description fields in (b) admin_groups.php and (c) groupcp.php, the (4) Theme Name field in (d) admin_styles.php, and the (5) Rank Title fi
nvd
CVE-2006-1603MEDIUMCVSS 4.3v2.0.192006-04-04
CVE-2006-1603 [MEDIUM] CVE-2006-1603: Cross-site scripting (XSS) vulnerability in profile.php in phpBB 2.0.19 allows remote attackers to i
Cross-site scripting (XSS) vulnerability in profile.php in phpBB 2.0.19 allows remote attackers to inject arbitrary web script or HTML via the cur_password parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
nvd
CVE-2006-0632MEDIUMCVSS 6.4v2.0.0v2.0.1+27 more2006-02-10
CVE-2006-0632 [MEDIUM] CVE-2006-0632: The gen_rand_string function in phpBB 2.0.19 uses insufficiently random data (small value space) to
The gen_rand_string function in phpBB 2.0.19 uses insufficiently random data (small value space) to create the activation key ("validation ID") that is sent by e-mail when establishing a password, which makes it easier for remote attackers to obtain the key and modify passwords for existing accounts or create new accounts.
nvd
CVE-2006-0438MEDIUMCVSS 5.0v2.0.0v2.0.1+27 more2006-02-06
CVE-2006-0438 [MEDIUM] CVE-2006-0438: Cross-site request forgery (CSRF) vulnerability in phpBB 2.0.19, when Link to off-site Avatar or bbc
Cross-site request forgery (CSRF) vulnerability in phpBB 2.0.19, when Link to off-site Avatar or bbcode (IMG) are enabled, allows remote attackers to perform unauthorized actions as a logged in user via a link or IMG tag in a user profile, as demonstrated using links to (1) admin/admin_users.php and (2) modcp.php.
nvd
CVE-2006-0437MEDIUMCVSS 4.3v2.0.6cv2.0.6d+15 more2006-02-06
CVE-2006-0437 [MEDIUM] CVE-2006-0437: Cross-site scripting (XSS) vulnerability in admin_smilies.php in phpBB 2.0.19 allows remote attacker
Cross-site scripting (XSS) vulnerability in admin_smilies.php in phpBB 2.0.19 allows remote attackers to inject arbitrary web script or HTML via Javascript events such as "onmouseover" in the (1) smile_url or (2) smile_emotion parameters, which bypasses a check for "" characters.
nvd
CVE-2006-0450MEDIUMCVSS 5.0v2.0.0v2.0.1+27 more2006-01-27
CVE-2006-0450 [MEDIUM] CVE-2006-0450: phpBB 2.0.19 and earlier allows remote attackers to cause a denial of service (application crash) by
phpBB 2.0.19 and earlier allows remote attackers to cause a denial of service (application crash) by (1) registering many users through profile.php or (2) using search.php to search in a certain way that confuses the database.
nvd
1 / 4Next →