Page 18 of 151 results (0.013 seconds)

CVSS: 5.0EPSS: 0%CPEs: 27EXPL: 0

A "missing request validation" error in phpBB 2 before 2.0.18 allows remote attackers to edit private messages of other users, probably by modifying certain parameters or other inputs. • http://secunia.com/advisories/18098 http://www.debian.org/security/2005/dsa-925 http://www.securityfocus.com/bid/15246 •

CVSS: 2.6EPSS: 2%CPEs: 1EXPL: 1

Cross-site scripting (XSS) vulnerability in phpBB 2.0.18, when "Allowed HTML tags" is enabled, allows remote attackers to inject arbitrary Javascript via a permitted HTML tag with " (quote) characters and active attributes such as onmouseover. • http://marc.info/?l=full-disclosure&m=113484567432679&w=2 http://secunia.com/advisories/18125 http://secunia.com/advisories/18252 http://securityreason.com/achievement_securityalert/29 http://securityreason.com/securityalert/269 http://www.osvdb.org/21803 http://www.phpbb.com/phpBB/viewtopic.php?t=352966 http://www.securityfocus.com/archive/1/420537/100/0/threaded http://www.vupen.com/english/advisories/2005/2991 http://www.vupen.com/english/advisories/2006/0010 •

CVSS: 5.0EPSS: 1%CPEs: 1EXPL: 0

admin/admin_disallow.php in phpBB 2.0.18 allows remote attackers to obtain the installation path via a direct request with a non-empty setmodules parameter, which causes an invalid append_sid function call that leaks the path in an error message. • http://marc.info/?l=full-disclosure&m=113484567432679&w=2 http://secunia.com/advisories/18125 http://secunia.com/advisories/18252 http://securityreason.com/achievement_securityalert/29 http://securityreason.com/securityalert/269 http://www.osvdb.org/21804 http://www.phpbb.com/phpBB/viewtopic.php?f=14&t=352966 http://www.securityfocus.com/archive/1/420537/100/0/threaded http://www.vupen.com/english/advisories/2005/2991 http://www.vupen.com/english/advisories/2006/0010 •

CVSS: 5.0EPSS: 0%CPEs: 1EXPL: 0

Directory traversal vulnerability in xs_edit.php in the eXtreme Styles phpBB module 2.2.1 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the edit parameter. • http://www.securityfocus.com/archive/1/418518/100/0/threaded •

CVSS: 5.0EPSS: 0%CPEs: 1EXPL: 0

xs_edit.php in the phpBB eXtreme Styles module 2.2.1 and earlier allows remote attackers to obtain the installation path of the application via an invalid viewbackup parameter. • http://www.securityfocus.com/archive/1/418518/100/0/threaded •