Page 13 of 63 results (0.014 seconds)

CVSS: 5.0EPSS: 0%CPEs: 4EXPL: 0

phpBB 2.0 through 2.0.3 generates names for uploaded avatar files with the hex-encoded IP address of the client system, which allows remote attackers to obtain client IP addresses. • http://online.securityfocus.com/archive/1/294560 http://www.iss.net/security_center/static/10323.php http://www.securityfocus.com/bid/5923 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 7.5EPSS: 2%CPEs: 6EXPL: 2

Cross-site scripting vulnerability in phpBB 2.0.0 (phpBB2) allows remote attackers to execute Javascript as other phpBB users by including a http:// and a double-quote (") in the [IMG] tag, which bypasses phpBB's security check, terminates the src parameter of the resulting HTML IMG tag, and injects the script. Vulnerabilidad de secuencias de comandos en sitios cruzados en phpBB 2.0.0 (phpBB) permite a atacantes remotos ejecutar Javascript como otros usuarios de phpBB incluyendo http:// y comillas dobles ("") en una etiquieta IMG, lo que evade la comprobación de seguridad de phpBB, termina el parámetro src de la etiqueta HTML IMG, e injecta la secuencia de comandos. • https://www.exploit-db.com/exploits/21486 http://online.securityfocus.com/archive/1/274273 http://www.iss.net/security_center/static/9178.php http://www.securityfocus.com/bid/4858 •

CVSS: 10.0EPSS: 11%CPEs: 4EXPL: 0

db.php in phpBB 2.0 (aka phpBB2) RC-3 and earlier allows remote attackers to execute arbitrary code from remote servers via the phpbb_root_path parameter. • http://archives.neohapsis.com/archives/bugtraq/2002-03/0221.html http://archives.neohapsis.com/archives/bugtraq/2002-03/0229.html http://online.securityfocus.com/archive/82/262600 http://phpbb.sourceforge.net/phpBB2/viewtopic.php?t=9483 http://prdownloads.sourceforge.net/phpbb/phpBB-2.0.1.zip http://www.iss.net/security_center/static/8476.php http://www.osvdb.org/4268 http://www.securityfocus.com/bid/4380 •