Skip to main content

Vendor/product archive

woltlab / burning_board CVEs

Beta · best-effort

36 CVEs tagged to woltlab / burning_board0 Critical, 22 High, 13 Medium, 1 Low, 0 Unrated.

CVE-2006-1034

Published Mar 7, 2006

Multiple cross-site scripting (XSS) vulnerabilities in Woltlab Burning Board (wBB) allow remote attackers to inject arbitrary web script or HTML via (1) the username parameter to…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0927

Published Feb 28, 2006

Multiple cross-site scripting (XSS) vulnerabilities in the JGS-XA JGS-Gallery Addon 4.0.0 and earlier for Woltlab Burning Board (wBB) 2.x allow remote attackers to inject arbitrar…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-3369

Published Oct 30, 2005

Multiple SQL injection vulnerabilities in the Info-DB module (info_db.php) in Woltlab Burning Board 2.7 and earlier allow remote attackers to execute arbitrary SQL commands and po…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-2673

Published Aug 23, 2005

SQL injection vulnerability in modcp.php in WoltLab Burning Board 2.2.2 and 2.3.3 allows remote authenticated attackers to execute arbitrary SQL commands via the (1) x or (2) y pa…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-1642

Published May 17, 2005

SQL injection vulnerability in the verify_email function in Woltlab Burning Board 2.x and earlier allows remote attackers to execute arbitrary SQL commands via the $email variable.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0661

Published May 2, 2005

SQL injection vulnerability in the getwbbuserdata function in session.php for Woltlab Burning Board 2.0.3 through 2.3.0 allows remote attackers to execute arbitrary SQL commands v…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-1327

Published May 2, 2005

Cross-site scripting (XSS) vulnerability in pms.php for Woltlab Burning Board 2.3.1 PL2 and earlier allows remote attackers to inject arbitrary web script or HTML via the folderid…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-1285

Published Apr 22, 2005

Cross-site scripting (XSS) vulnerability in thread.php in WoltLab Burning Board 2.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the hilight pa…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1505

Published Apr 2, 2003

SQL injection vulnerability in board.php for WoltLab Burning Board (wBB) 2.0 RC 1 and earlier allows remote attackers to modify the database and possibly gain privileges via the b…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-2021

Published Dec 31, 2002

Cross-site scripting (XSS) vulnerability in WoltLab Burning Board (wbboard) 1.1.1 allows remote attackers to inject arbitrary web script or HTML via the message parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-0903

Published Oct 4, 2002

register.php for WoltLab Burning Board (wbboard) 1.1.1 uses a small number of random values for the "code" parameter that is provided to action.php to approve a new registration,…

CVSS 7.5 · High
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort
Showing 26-36 of 36 CVEsPage 2 of 2