Searching punbb software vulnerabilities


admin_loader.php in PunBB 1.2.1 allows remote a


admin_loader.php in PunBB 1.2.1 allows remote attackers to read arbitrary files via the plugin parameter.


Cross-site scripting (XSS) vulnerability in Pun


Cross-site scripting (XSS) vulnerability in PunBB 1.2.3 allows remote attackers to inject arbitrary web script or HTML via the (1) email or (2) Jabber parameters.


SQL injection vulnerability in profile.php in P


SQL injection vulnerability in profile.php in PunBB 1.2.4 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a change_email action.


Cross-site scripting (XSS) vulnerability in Pun


Cross-site scripting (XSS) vulnerability in PunBB before 1.2.5 allows remote attackers to inject arbitrary web script or HTML.


Cross-site scripting (XSS) vulnerability in Pun


Cross-site scripting (XSS) vulnerability in PunBB before 1.2.8 allows remote attackers to inject arbitrary web script or HTML via the "forgotten e-mail" feature.


PunBB before 1.2.8 allows remote attackers to p


PunBB before 1.2.8 allows remote attackers to perform "code inclusion" via the user language selection.


PHP remote file inclusion vulnerability in comm


PHP remote file inclusion vulnerability in common.php in PunBB 1.1.2 through 1.1.5 allows remote attackers to execute arbitrary code via the pun_root parameter.


SQL injection vulnerability in search.php in Pu


SQL injection vulnerability in search.php in PunBB 1.2.7 and 1.2.8 allows remote attackers to execute arbitrary SQL commands via the old_searches parameter.


Cross-site scripting (XSS) vulnerability in Pun


Cross-site scripting (XSS) vulnerability in PunBB 1.2.6 and earlier allows remote attackers to inject arbitrary web script or HTML via Javascript contained in nested, malformed BBcode url tags.


PunBB 1.2.9, when used alone or with F-ART BLOG


PunBB 1.2.9, when used alone or with F-ART BLOG:CMS, includes config.php before calling the unregister_globals function, which allows attackers to obtain unspecified sensitive information.


PunBB 1.2.9 does not require password entry whe


PunBB 1.2.9 does not require password entry when changing the e-mail address in an account's profile, which might allow an attacker to make an address change via a hijacked login session.


PunBB 1.2.10 and earlier allows remote attacker


PunBB 1.2.10 and earlier allows remote attackers to cause a denial of service (resource consumption) by registering many user accounts quickly.


PunBB 1.2.10 and earlier allows remote attacker


PunBB 1.2.10 and earlier allows remote attackers to conduct brute force guessing attacks for an account's password, which may be as short as 4 characters.


register.php in PunBB 1.2.10 allows remote atta


register.php in PunBB 1.2.10 allows remote attackers to cause an unspecified denial of service via a flood of new user registrations.


Cross-site scripting (XSS) vulnerability in Rev


Cross-site scripting (XSS) vulnerability in RevoBoard 1.8, as derived from PunBB, allows remote attackers to inject arbitrary web script or HTML via a substitution cipher of the email tag, which is transformed when the application's e-mail address obfuscator reverses the transformation. NOTE: it is not clear whether this is a site-specific issue; however, the claimed codebase relationship with PunBB might be relevant.


Cross-site scripting (XSS) vulnerability in mis


Cross-site scripting (XSS) vulnerability in misc.php in PunBB 1.2.11 allows remote attackers to inject arbitrary web script or HTML via the req_message parameter, because the value of the redirect_url parameter is not sanitized.


Cross-site scripting (XSS) vulnerability in Pun


Cross-site scripting (XSS) vulnerability in PunBB 1.2.11 allows remote authenticated administrators to inject arbitrary HTML or web script to other administrators via the "Admin note" feature, a different vulnerability than CVE-2006-2227.


SQL injection vulnerability in search.php in Pu


SQL injection vulnerability in search.php in PunBB before 1.2.14, when the PHP installation is vulnerable to CVE-2006-3017, allows remote attackers to execute arbitrary SQL commands via the result_list array parameter, which is not initialized.


PunBB uses a predictable cookie_seed value that


PunBB uses a predictable cookie_seed value that can be derived from the time of registration of the superadmin account (installation time), which might allow local users to perform unauthorized actions.


Multiple SQL injection vulnerabilities in PunBB


Multiple SQL injection vulnerabilities in PunBB before 1.2.14 allow remote authenticated administrators to execute arbitrary SQL commands via unspecified vectors.


Software vulnerabilities results 1 to 20 of 30     
Page: 12