Skip to main content

Vendor archive

woltlab CVEs

Beta · best-effort

46 CVEs tagged to vendor woltlab0 Critical, 29 High, 16 Medium, 1 Low, 0 Unrated.

CVE-2008-7192

Published Sep 9, 2009

Cross-site request forgery (CSRF) vulnerability in index.php in WoltLab Burning Board (wBB) 3.0.1, and possibly other 3.x versions, allows remote attackers to hijack the authentic…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5863

Published Jan 6, 2009

SQL injection vulnerability in locator.php in the Userlocator module 3.0 for Woltlab Burning Board (wBB) allows remote attackers to execute arbitrary SQL commands via the y parame…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-1716

Published Apr 9, 2008

Cross-site scripting (XSS) vulnerability in WoltLab Community Framework (WCF) 1.0.6 in WoltLab Burning Board 3.0.5 allows remote attackers to inject arbitrary web script or HTML v…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1717

Published Apr 9, 2008

WoltLab Community Framework (WCF) 1.0.6 in WoltLab Burning Board 3.0.5 allows remote attackers to obtain the full path via invalid (1) page and (2) form parameters, which leaks th…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1323

Published Mar 13, 2008

Cross-site request forgery (CSRF) vulnerability in index.php in WoltLab Burning Board Lite (wBB) 2 Beta 1 allows remote attackers to delete threads as other users via the ThreadDe…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0857

Published Feb 21, 2008

SQL injection vulnerability in index.php in WoltLab Burning Board 3.0.3 PL 1 allows remote attackers to execute arbitrary SQL commands via the sortOrder parameter to the PMList pa…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0472

Published Jan 29, 2008

Cross-site request forgery (CSRF) vulnerability in modcp.php in Woltlab Burning Board (wBB) 2.3.6 PL2 allows remote attackers to delete threads as moderators or administrators via…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6518

Published Dec 24, 2007

Multiple SQL injection vulnerabilities in search.php in WoltLab Burning Board (wBB) Lite 1.0.2 pl3e allow remote attackers to execute arbitrary SQL commands via the (1) showposts,…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-1518

Published Mar 20, 2007

SQL injection vulnerability in usergroups.php in Woltlab Burning Board (wBB) 2.x allows remote attackers to execute arbitrary SQL commands via the array index of the applicationid…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0812

Published Feb 7, 2007

SQL injection vulnerability in pms.php in Woltlab Burning Board (wBB) Lite 1.0.2pl3e and earlier allows remote authenticated users to execute arbitrary SQL commands via the pmid[0…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0388

Published Jan 19, 2007

SQL injection vulnerability in search.php in Woltlab Burning Board (wBB) 1.0.2 and earlier, and 2.3.6 and earlier in the 2.x series, allows remote attackers to execute arbitrary S…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6289

Published Dec 5, 2006

Woltlab Burning Board (wBB) Lite 1.0.2 does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash va…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6237

Published Dec 3, 2006

SQL injection vulnerability in the decode_cookie function in thread.php in Woltlab Burning Board Lite 1.0.2 allows remote attackers to execute arbitrary SQL commands via the threa…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-5508

Published Oct 25, 2006

Multiple SQL injection vulnerabilities in addentry.php in WoltLab Burning Book 1.1.2 allow remote attackers to execute arbitrary SQL commands via (1) the n parameter and (2) the U…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-5509

Published Oct 25, 2006

Eval injection vulnerability in addentry.php in WoltLab Burning Book 1.1.2 allows remote attackers to execute arbitrary PHP code via crafted POST requests that store PHP code in a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-5029

Published Sep 27, 2006

SQL injection vulnerability in thread.php in WoltLab Burning Board (wBB) 2.3.x allows remote attackers to obtain the version numbers of PHP, MySQL, and wBB via the page parameter.…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4317

Published Aug 24, 2006

Cross-site scripting (XSS) vulnerability in attachment.php in WoltLab Burning Board (WBB) 2.3.5 allows remote attackers to inject arbitrary web script or HTML via a GIF image that…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3254

Published Jun 28, 2006

SQL injection vulnerability in newthread.php in Woltlab Burning Board (WBB) 2.0 RC2 allows remote attackers to execute arbitrary SQL commands via the boardid parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-3255

Published Jun 28, 2006

SQL injection vulnerability in showmods.php in Woltlab Burning Board (WBB) 1.2 allows remote attackers to execute arbitrary SQL commands via the boardid parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-3256

Published Jun 28, 2006

SQL injection vulnerability in report.php in Woltlab Burning Board (WBB) 2.3.1 allows remote attackers to execute arbitrary SQL commands via the postid parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 46 CVEsPage 1 of 2