Skip to main content

Vendor archive

woltlab CVEs

Beta · best-effort

46 CVEs tagged to vendor woltlab0 Critical, 29 High, 16 Medium, 1 Low, 0 Unrated.

CVE-2006-3218

Published Jun 24, 2006

SQL injection vulnerability in profile.php in Woltlab Burning Board (WBB) 2.1.6 allows remote attackers to execute arbitrary SQL commands via the userid parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-3219

Published Jun 24, 2006

SQL injection vulnerability in thread.php in Woltlab Burning Board (WBB) 2.2.2 allows remote attackers to execute arbitrary SQL commands via the threadid parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-3220

Published Jun 24, 2006

SQL injection vulnerability in studienplatztausch.php in Woltlab Burning Board (WBB) 2.2.1 allows remote attackers to execute arbitrary SQL commands via the sid parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-2792

Published Jun 3, 2006

SQL injection vulnerability in misc.php in Woltlab Burning Board (WBB) 2.3.4 allows remote attackers to execute arbitrary SQL commands via the sid parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-2569

Published May 24, 2006

SQL injection vulnerability in links.php in 4R Linklist 1.0 RC2 and earlier, a module for Woltlab Burning Board, allows remote attackers to execute arbitrary SQL commands via the…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-1324

Published Mar 21, 2006

Cross-site scripting (XSS) vulnerability in acp/lib/class_db_mysql.php in Woltlab Burning Board (wBB) 2.3.4 allows remote attackers to inject arbitrary web script or HTML via the…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1215

Published Mar 14, 2006

Cross-site scripting (XSS) vulnerability in misc.php in Woltlab Burning Board (wBB) 2.3.4 allows remote attackers to inject arbitrary web script or HTML via the percent parameter.…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1034

Published Mar 7, 2006

Multiple cross-site scripting (XSS) vulnerabilities in Woltlab Burning Board (wBB) allow remote attackers to inject arbitrary web script or HTML via (1) the username parameter to…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0927

Published Feb 28, 2006

Multiple cross-site scripting (XSS) vulnerabilities in the JGS-XA JGS-Gallery Addon 4.0.0 and earlier for Woltlab Burning Board (wBB) 2.x allow remote attackers to inject arbitrar…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-3369

Published Oct 30, 2005

Multiple SQL injection vulnerabilities in the Info-DB module (info_db.php) in Woltlab Burning Board 2.7 and earlier allow remote attackers to execute arbitrary SQL commands and po…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-2673

Published Aug 23, 2005

SQL injection vulnerability in modcp.php in WoltLab Burning Board 2.2.2 and 2.3.3 allows remote authenticated attackers to execute arbitrary SQL commands via the (1) x or (2) y pa…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-1642

Published May 17, 2005

SQL injection vulnerability in the verify_email function in Woltlab Burning Board 2.x and earlier allows remote attackers to execute arbitrary SQL commands via the $email variable.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0216

Published May 2, 2005

Cross-site scripting (XSS) vulnerability in formmail.php in Woltlab Burning Board Lite 1.0.0, 1.0.1e, and possibly other versions, allows remote attackers to inject arbitrary web…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0661

Published May 2, 2005

SQL injection vulnerability in the getwbbuserdata function in session.php for Woltlab Burning Board 2.0.3 through 2.3.0 allows remote attackers to execute arbitrary SQL commands v…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-1327

Published May 2, 2005

Cross-site scripting (XSS) vulnerability in pms.php for Woltlab Burning Board 2.3.1 PL2 and earlier allows remote attackers to inject arbitrary web script or HTML via the folderid…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-1285

Published Apr 22, 2005

Cross-site scripting (XSS) vulnerability in thread.php in WoltLab Burning Board 2.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the hilight pa…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0284

Published Jan 10, 2005

SQL injection vulnerability in addentry.php in Woltlab Burning Book 1.0 Gold, 1.1.1e, and possibly other versions, allows remote attackers to execute arbitrary SQL commands via th…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-1505

Published Apr 2, 2003

SQL injection vulnerability in board.php for WoltLab Burning Board (wBB) 2.0 RC 1 and earlier allows remote attackers to modify the database and possibly gain privileges via the b…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-2021

Published Dec 31, 2002

Cross-site scripting (XSS) vulnerability in WoltLab Burning Board (wbboard) 1.1.1 allows remote attackers to inject arbitrary web script or HTML via the message parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-0903

Published Oct 4, 2002

register.php for WoltLab Burning Board (wbboard) 1.1.1 uses a small number of random values for the "code" parameter that is provided to action.php to approve a new registration,…

CVSS 7.5 · High
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort
Showing 26-46 of 46 CVEsPage 2 of 2