CVE-2008-7143
https://notcve.org/view.php?id=CVE-2008-7143
phpBB 2.0.23 includes the session ID in a request to modcp.php when the moderator or administrator closes a thread, which allows remote attackers to hijack the session via a post in the thread containing a URL to a remotely hosted image, which might include the session ID in the Referer header. phpBB v2.0.23 incluye la el ID de sesión en una petición a modcp.php cuando el moderador o administrador cierra un hilo, lo que permite a atacantes remotos secuestrar la sesión a través de un envío en el hilo conteniendo una URL a una imagen hospedada remotamente, que permite incluir el ID de sesión en la cabercera Referer. • http://osvdb.org/51121 http://www.securityfocus.com/archive/1/489815/100/0/threaded • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2008-6506
https://notcve.org/view.php?id=CVE-2008-6506
Unspecified vulnerability in phpBB before 3.0.4 allows attackers to bypass intended access restrictions and activate de-activated accounts via unknown vectors. Vulnerabilidad no espécificada en phpBB anteriores a v3.0.4 permite a atacantes saltarse las restricciones de seguridad y activar cuentas desactivadas, a través de vectores desconocidos. • http://secunia.com/advisories/33166 http://www.openwall.com/lists/oss-security/2009/02/06/2 http://www.osvdb.org/50806 http://www.phpbb.com/community/viewtopic.php?f=14&t=1352565 http://www.phpbb.com/support/documents.php?mode=changelog&version=3#v303 http://www.securityfocus.com/bid/32842 https://exchange.xforce.ibmcloud.com/vulnerabilities/47370 • CWE-264: Permissions, Privileges, and Access Controls •
CVE-2008-3224
https://notcve.org/view.php?id=CVE-2008-3224
Unspecified vulnerability in phpBB before 3.0.1 has unknown impact and attack vectors related to "urls gone through redirect() being used within login_box()." Vulnerabilidad sin especificar en phpBB 3.0.1 tiene un impacto desconocido y vectores de ataque relacionados con "URLs a las que se accede a través de redirect() dentro de login_box ()". • http://www.openwall.com/lists/oss-security/2008/07/12/1 http://www.phpbb.com/community/viewtopic.php?f=14&t=1059565&sid=2d3a6352a484588e1ad80f09dd19fe33 https://exchange.xforce.ibmcloud.com/vulnerabilities/44208 •
CVE-2008-1766
https://notcve.org/view.php?id=CVE-2008-1766
Multiple unspecified vulnerabilities in phpBB before 3.0.1 have unknown impact and attack vectors, related to "two minor security-related bugs." Múltiples vulnerabilidades no especificadas en phpBB anterior a 3.0.1 tienen un impacto desconocido y vectores de ataque, referidos a " dos errores menores relacionados con la seguridad" • http://www.phpbb.com/community/viewtopic.php?f=14&t=879735 http://www.vupen.com/english/advisories/2008/1236/references https://exchange.xforce.ibmcloud.com/vulnerabilities/41886 •
CVE-2006-6421 – phpBB 2.0.21 - 'privmsg.php' HTML Injection
https://notcve.org/view.php?id=CVE-2006-6421
Cross-site scripting (XSS) vulnerability in the private message box implementation (privmsg.php) in phpBB 2.0.x allows remote authenticated users to inject arbitrary web script or HTML via the "Message body" field in a message to a non-existent user. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en el buzón de mensajes privados en phpBB 2.0.x permite a un usuario remoto validado inyectar secuencias de comandos web o HTML a través del campo "cuerpo de mensaje" de un mensaje a un usuario no existente. • https://www.exploit-db.com/exploits/29442 http://secunia.com/advisories/23283 http://securityreason.com/securityalert/2005 http://www.phpbb.com/phpBB/viewtopic.php?f=14&t=489624 http://www.securityfocus.com/archive/1/453774/100/0/threaded http://www.securityfocus.com/archive/1/456579/100/0/threaded http://www.securityfocus.com/archive/1/456728/100/100/threaded http://www.securityfocus.com/archive/1/456784/100/100/threaded http://www.securityfocus.com/bid/21806 http:/ •