CVE-2005-4686
https://notcve.org/view.php?id=CVE-2005-4686
PunBB 1.2.9, when used alone or with F-ART BLOG:CMS, includes config.php before calling the unregister_globals function, which allows attackers to obtain unspecified sensitive information. • http://secunia.com/advisories/17425 http://secunia.com/advisories/17433 http://www.punbb.org/changelogs/1.2.9_to_1.2.10.txt http://www.securityfocus.com/bid/15328 •
CVE-2005-3518 – PunBB 1.2.x - 'search.php' SQL Injection
https://notcve.org/view.php?id=CVE-2005-3518
SQL injection vulnerability in search.php in PunBB 1.2.7 and 1.2.8 allows remote attackers to execute arbitrary SQL commands via the old_searches parameter. • https://www.exploit-db.com/exploits/26350 http://marc.info/?l=bugtraq&m=112939699128430&w=2 http://secunia.com/advisories/17227 http://securityreason.com/securityalert/87 http://www.kapda.ir/advisory-91.html http://www.osvdb.org/20018 http://www.punbb.org/changelogs/1.2.8_to_1.2.9.txt http://www.securityfocus.net/bid/15114 https://exchange.xforce.ibmcloud.com/vulnerabilities/22760 •