Skip to main content

Vendor/product archive

woltlab / burning_board CVEs

Beta · best-effort

36 CVEs tagged to woltlab / burning_board0 Critical, 22 High, 13 Medium, 1 Low, 0 Unrated.

CVE-2008-7192

Published Sep 9, 2009

Cross-site request forgery (CSRF) vulnerability in index.php in WoltLab Burning Board (wBB) 3.0.1, and possibly other 3.x versions, allows remote attackers to hijack the authentic…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5863

Published Jan 6, 2009

SQL injection vulnerability in locator.php in the Userlocator module 3.0 for Woltlab Burning Board (wBB) allows remote attackers to execute arbitrary SQL commands via the y parame…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-1716

Published Apr 9, 2008

Cross-site scripting (XSS) vulnerability in WoltLab Community Framework (WCF) 1.0.6 in WoltLab Burning Board 3.0.5 allows remote attackers to inject arbitrary web script or HTML v…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1717

Published Apr 9, 2008

WoltLab Community Framework (WCF) 1.0.6 in WoltLab Burning Board 3.0.5 allows remote attackers to obtain the full path via invalid (1) page and (2) form parameters, which leaks th…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0857

Published Feb 21, 2008

SQL injection vulnerability in index.php in WoltLab Burning Board 3.0.3 PL 1 allows remote attackers to execute arbitrary SQL commands via the sortOrder parameter to the PMList pa…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0472

Published Jan 29, 2008

Cross-site request forgery (CSRF) vulnerability in modcp.php in Woltlab Burning Board (wBB) 2.3.6 PL2 allows remote attackers to delete threads as moderators or administrators via…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-1518

Published Mar 20, 2007

SQL injection vulnerability in usergroups.php in Woltlab Burning Board (wBB) 2.x allows remote attackers to execute arbitrary SQL commands via the array index of the applicationid…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0388

Published Jan 19, 2007

SQL injection vulnerability in search.php in Woltlab Burning Board (wBB) 1.0.2 and earlier, and 2.3.6 and earlier in the 2.x series, allows remote attackers to execute arbitrary S…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-5029

Published Sep 27, 2006

SQL injection vulnerability in thread.php in WoltLab Burning Board (wBB) 2.3.x allows remote attackers to obtain the version numbers of PHP, MySQL, and wBB via the page parameter.…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4317

Published Aug 24, 2006

Cross-site scripting (XSS) vulnerability in attachment.php in WoltLab Burning Board (WBB) 2.3.5 allows remote attackers to inject arbitrary web script or HTML via a GIF image that…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3254

Published Jun 28, 2006

SQL injection vulnerability in newthread.php in Woltlab Burning Board (WBB) 2.0 RC2 allows remote attackers to execute arbitrary SQL commands via the boardid parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-3255

Published Jun 28, 2006

SQL injection vulnerability in showmods.php in Woltlab Burning Board (WBB) 1.2 allows remote attackers to execute arbitrary SQL commands via the boardid parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-3256

Published Jun 28, 2006

SQL injection vulnerability in report.php in Woltlab Burning Board (WBB) 2.3.1 allows remote attackers to execute arbitrary SQL commands via the postid parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-3218

Published Jun 24, 2006

SQL injection vulnerability in profile.php in Woltlab Burning Board (WBB) 2.1.6 allows remote attackers to execute arbitrary SQL commands via the userid parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-3219

Published Jun 24, 2006

SQL injection vulnerability in thread.php in Woltlab Burning Board (WBB) 2.2.2 allows remote attackers to execute arbitrary SQL commands via the threadid parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-3220

Published Jun 24, 2006

SQL injection vulnerability in studienplatztausch.php in Woltlab Burning Board (WBB) 2.2.1 allows remote attackers to execute arbitrary SQL commands via the sid parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-2792

Published Jun 3, 2006

SQL injection vulnerability in misc.php in Woltlab Burning Board (WBB) 2.3.4 allows remote attackers to execute arbitrary SQL commands via the sid parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-2569

Published May 24, 2006

SQL injection vulnerability in links.php in 4R Linklist 1.0 RC2 and earlier, a module for Woltlab Burning Board, allows remote attackers to execute arbitrary SQL commands via the…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-1324

Published Mar 21, 2006

Cross-site scripting (XSS) vulnerability in acp/lib/class_db_mysql.php in Woltlab Burning Board (wBB) 2.3.4 allows remote attackers to inject arbitrary web script or HTML via the…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1215

Published Mar 14, 2006

Cross-site scripting (XSS) vulnerability in misc.php in Woltlab Burning Board (wBB) 2.3.4 allows remote attackers to inject arbitrary web script or HTML via the percent parameter.…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 36 CVEsPage 1 of 2