Page 5 of 110 results (0.020 seconds)

CVSS: 5.0EPSS: 0%CPEs: 4EXPL: 0

Unspecified vulnerability in phpBB before 3.0.4 allows attackers to obtain sensitive information via unknown vectors related to the lack of password prompts for a private message that quotes a post in a password-protected forum. Una vulnerabilidad sin especificar en phpBB antes de la versión 3.0.4 permite a atacantes obtener información sensible a través de vectores desconocidos relacionados con la ausencia de petición de contraseña en un mensaje privado que cita una entrada de un foro protegido por contraseña. • http://secunia.com/advisories/33166 http://www.openwall.com/lists/oss-security/2009/02/06/2 http://www.osvdb.org/50806 http://www.phpbb.com/community/viewtopic.php?f=14&t=1352565 http://www.phpbb.com/support/documents.php?mode=changelog&version=3#v303 •

CVSS: 5.0EPSS: 0%CPEs: 19EXPL: 0

Unspecified vulnerability in phpBB before 3.0.4 allows attackers to bypass intended access restrictions and activate de-activated accounts via unknown vectors. Vulnerabilidad no espécificada en phpBB anteriores a v3.0.4 permite a atacantes saltarse las restricciones de seguridad y activar cuentas desactivadas, a través de vectores desconocidos. • http://secunia.com/advisories/33166 http://www.openwall.com/lists/oss-security/2009/02/06/2 http://www.osvdb.org/50806 http://www.phpbb.com/community/viewtopic.php?f=14&t=1352565 http://www.phpbb.com/support/documents.php?mode=changelog&version=3#v303 http://www.securityfocus.com/bid/32842 https://exchange.xforce.ibmcloud.com/vulnerabilities/47370 • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 5.0EPSS: 0%CPEs: 1EXPL: 0

The search function in phpBB 2.x provides a search_id value that leaks the state of PHP's PRNG, which allows remote attackers to obtain potentially sensitive information, as demonstrated by a cross-application attack against WordPress, a different vulnerability than CVE-2006-0632. La función de búsqueda en phpBB 2.x proporciona un valor search_id que pierde el estado de PHP's PRNG, el cual permite a los atacantes remoto obtener potencialmente información sensible, como se demuestra por un ataque de aplicaciones cruzadas contra WordPress, vulnerabilidad diferente a CVE-2006-0632. • http://www.suspekt.org/2008/08/17/mt_srand-and-not-so-random-numbers https://exchange.xforce.ibmcloud.com/vulnerabilities/45415 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 10.0EPSS: 0%CPEs: 9EXPL: 0

Unspecified vulnerability in phpBB before 3.0.1 has unknown impact and attack vectors related to "urls gone through redirect() being used within login_box()." Vulnerabilidad sin especificar en phpBB 3.0.1 tiene un impacto desconocido y vectores de ataque relacionados con "URLs a las que se accede a través de redirect() dentro de login_box ()". • http://www.openwall.com/lists/oss-security/2008/07/12/1 http://www.phpbb.com/community/viewtopic.php?f=14&t=1059565&sid=2d3a6352a484588e1ad80f09dd19fe33 https://exchange.xforce.ibmcloud.com/vulnerabilities/44208 •

CVSS: 10.0EPSS: 0%CPEs: 8EXPL: 0

Multiple unspecified vulnerabilities in phpBB before 3.0.1 have unknown impact and attack vectors, related to "two minor security-related bugs." Múltiples vulnerabilidades no especificadas en phpBB anterior a 3.0.1 tienen un impacto desconocido y vectores de ataque, referidos a " dos errores menores relacionados con la seguridad" • http://www.phpbb.com/community/viewtopic.php?f=14&t=879735 http://www.vupen.com/english/advisories/2008/1236/references https://exchange.xforce.ibmcloud.com/vulnerabilities/41886 •