Page 2 of 27 results (0.003 seconds)

CVSS: 4.3EPSS: 0%CPEs: 20EXPL: 0

Cross-site scripting (XSS) vulnerability in userlist.php in PunBB before 1.2.20 allows remote attackers to inject arbitrary web script or HTML via the p parameter. Vulnerabilidad de secuencias de comandos en sitios cruzados XSS en el archivo userlist.php en PunBB, versiones anteriores a 1.2.20, que permite a los atacantes remotos inyectar una secuencia arbitraria de comandos web o HTML a través del parámetro p. • http://punbb.informer.com/download/changelogs/1.2.19_to_1.2.20.txt http://punbb.informer.com/forums/topic/19682/punbb-1220-and-13rc-hotfix-released http://www.openwall.com/lists/oss-security/2008/09/09/10 http://www.openwall.com/lists/oss-security/2008/09/09/2 http://www.securityfocus.com/bid/31082 https://exchange.xforce.ibmcloud.com/vulnerabilities/45046 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 4.3EPSS: 0%CPEs: 35EXPL: 0

Multiple cross-site scripting (XSS) vulnerabilities in PunBB before 1.2.19 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors in (1) include/parser.php and (2) moderate.php. Múltiples vulnerabilidades de tipo cross-site scripting (XSS) en PunBB anterior a versión 1.2.19, permiten a los atacantes remotos inyectar script web o HTML arbitrario por medio de vectores no especificados en los archivos (1) include/parser.php y (2) moderate.php. • http://punbb.informer.com http://punbb.informer.com/download/changelogs/1.2.17_to_1.2.19.txt http://punbb.informer.com/forums/topic/19539/punbb-1219 http://secunia.com/advisories/31219 http://www.securityfocus.com/bid/30396 https://exchange.xforce.ibmcloud.com/vulnerabilities/44009 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 10.0EPSS: 1%CPEs: 34EXPL: 0

Unspecified vulnerability in PunBB before 1.2.19 allows remote attackers to inject arbitrary SMTP commands via unknown vectors. Vulnerabilidad sin especificar en PunBB anterior a 1.2.19, permite a atacantes remotos inyectar comandos SMTP a través de vectores no especificados. • http://punbb.informer.com http://punbb.informer.com/download/changelogs/1.2.17_to_1.2.19.txt http://punbb.informer.com/forums/topic/19539/punbb-1219 http://secunia.com/advisories/31219 http://www.securityfocus.com/bid/30395 https://exchange.xforce.ibmcloud.com/vulnerabilities/44010 • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVSS: 3.5EPSS: 1%CPEs: 31EXPL: 1

The password reset feature in PunBB 1.2.16 and earlier uses predictable random numbers based on the system time, which allows remote authenticated users to determine the new password via a brute force attack on a seed that is based on the approximate creation time of the targeted account. NOTE: this issue might be related to CVE-2006-5737. La característica de reinicialización de contraseña en PunBB 1.2.16 y anteriores utiliza números aleatorios previsibles basados en la hora del sistema, lo que permite a usuarios autentificados remotamente averiguar la nueva contraseña a través de un ataque de fuerza bruta con una semilla que está basada en la creación aproximada de la cuenta objetivo. NOTA: este caso podría estar relacionado con CVE-2006-5737. • https://www.exploit-db.com/exploits/5165 http://osvdb.org/45561 http://punbb.org/download/changelogs/1.2.16_to_1.2.17.txt http://punbb.org/forums/viewtopic.php?id=18460 http://secunia.com/advisories/29043 http://sektioneins.de/advisories/SE-2008-01.txt http://www.securityfocus.com/archive/1/488408/100/200/threaded http://www.securityfocus.com/bid/27908 • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 4.3EPSS: 0%CPEs: 31EXPL: 0

Cross-site scripting (XSS) vulnerability in PunBB 1.2.16 and earlier allows remote attackers to inject arbitrary web script or HTML via the get_host parameter to moderate.php. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en PunBB 1.2.16 y anteriores permite a atacantes remotos inyectar secuencias de comandos web o HTML a través del parámetro get_host parameter a moderate.php. • http://osvdb.org/45561 http://punbb.org/download/changelogs/1.2.16_to_1.2.17.txt http://secunia.com/advisories/29043 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •