Page 6 of 179 results (0.005 seconds)

CVSS: 5.0EPSS: 0%CPEs: 1EXPL: 0

The search function in phpBB 2.x provides a search_id value that leaks the state of PHP's PRNG, which allows remote attackers to obtain potentially sensitive information, as demonstrated by a cross-application attack against WordPress, a different vulnerability than CVE-2006-0632. La función de búsqueda en phpBB 2.x proporciona un valor search_id que pierde el estado de PHP's PRNG, el cual permite a los atacantes remoto obtener potencialmente información sensible, como se demuestra por un ataque de aplicaciones cruzadas contra WordPress, vulnerabilidad diferente a CVE-2006-0632. • http://www.suspekt.org/2008/08/17/mt_srand-and-not-so-random-numbers https://exchange.xforce.ibmcloud.com/vulnerabilities/45415 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 10.0EPSS: 0%CPEs: 9EXPL: 0

Unspecified vulnerability in phpBB before 3.0.1 has unknown impact and attack vectors related to "urls gone through redirect() being used within login_box()." Vulnerabilidad sin especificar en phpBB 3.0.1 tiene un impacto desconocido y vectores de ataque relacionados con "URLs a las que se accede a través de redirect() dentro de login_box ()". • http://www.openwall.com/lists/oss-security/2008/07/12/1 http://www.phpbb.com/community/viewtopic.php?f=14&t=1059565&sid=2d3a6352a484588e1ad80f09dd19fe33 https://exchange.xforce.ibmcloud.com/vulnerabilities/44208 •

CVSS: 10.0EPSS: 0%CPEs: 8EXPL: 0

Multiple unspecified vulnerabilities in phpBB before 3.0.1 have unknown impact and attack vectors, related to "two minor security-related bugs." Múltiples vulnerabilidades no especificadas en phpBB anterior a 3.0.1 tienen un impacto desconocido y vectores de ataque, referidos a " dos errores menores relacionados con la seguridad" • http://www.phpbb.com/community/viewtopic.php?f=14&t=879735 http://www.vupen.com/english/advisories/2008/1236/references https://exchange.xforce.ibmcloud.com/vulnerabilities/41886 •

CVSS: 7.5EPSS: 1%CPEs: 2EXPL: 2

Directory traversal vulnerability in forum/irc/irc.php in the PJIRC 0.5 module for phpBB allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the phpEx parameter. Vulnerabilidad de salto de directorio en forum/irc/irc.php del módulo PJIRC 0.5 para phpBB permite a atacantes remotos incluir y ejecutar archivos locales de su elección a través de .. (punto punto) en el parámetro phpEx. • https://www.exploit-db.com/exploits/31535 http://securityreason.com/securityalert/3790 http://www.securityfocus.com/archive/1/490070/100/0/threaded http://www.securityfocus.com/bid/28446 https://exchange.xforce.ibmcloud.com/vulnerabilities/41456 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVSS: 7.5EPSS: 1%CPEs: 2EXPL: 2

Directory traversal vulnerability in admin/admin_xs.php in eXtreme Styles module (XS-Mod) 2.3.1 and 2.4.0 for phpBB allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the phpEx parameter. NOTE: some of these details are obtained from third party information. Una vulnerabilidad de salto de directorio en el archivo admin/admin_xs.php en el módulo eXtreme Styles (XS-Mod) versiones 2.3.1 y 2.4.0 para phpBB, permite a los atacantes remotos incluir y ejecutar archivos arbitrarios por medio de un .. (punto punto) en el parámetro phpEx. • https://www.exploit-db.com/exploits/5301 http://secunia.com/advisories/29487 http://www.securityfocus.com/bid/28432 https://exchange.xforce.ibmcloud.com/vulnerabilities/41404 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •