Page 6 of 93 results (0.006 seconds)

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 0

Multiple cross-site scripting (XSS) vulnerabilities in phpBB 2.0.19 allow remote attackers to inject arbitrary web script or HTML via the (1) Site Description field in (a) admin_board.php, the (2) Group name and (3) Group description fields in (b) admin_groups.php and (c) groupcp.php, the (4) Theme Name field in (d) admin_styles.php, and the (5) Rank Title field in (e) admin_ranks.php. NOTE: the profile.php/Current password vector is already covered by CVE-2006-1603. • http://osvdb.org/ref/24/24353-phpbb.txt http://www.osvdb.org/24354 http://www.osvdb.org/24355 http://www.osvdb.org/24356 http://www.osvdb.org/24357 •

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 0

Cross-site scripting (XSS) vulnerability in profile.php in phpBB 2.0.19 allows remote attackers to inject arbitrary web script or HTML via the cur_password parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. • http://osvdb.org/ref/24/24353-phpbb.txt http://secunia.com/advisories/19494 http://www.osvdb.org/24353 http://www.securityfocus.com/bid/17355 http://www.vupen.com/english/advisories/2006/1191 https://exchange.xforce.ibmcloud.com/vulnerabilities/25599 •

CVSS: 6.4EPSS: 1%CPEs: 29EXPL: 1

The gen_rand_string function in phpBB 2.0.19 uses insufficiently random data (small value space) to create the activation key ("validation ID") that is sent by e-mail when establishing a password, which makes it easier for remote attackers to obtain the key and modify passwords for existing accounts or create new accounts. • http://secunia.com/advisories/18727 http://www.osvdb.org/22949 http://www.r-security.net/tutorials/view/readtutorial.php?id=4 http://www.securityfocus.com/archive/1/424074/100/0/threaded http://www.vupen.com/english/advisories/2006/0461 https://exchange.xforce.ibmcloud.com/vulnerabilities/24573 •

CVSS: 4.3EPSS: 0%CPEs: 17EXPL: 1

Cross-site scripting (XSS) vulnerability in admin_smilies.php in phpBB 2.0.19 allows remote attackers to inject arbitrary web script or HTML via Javascript events such as "onmouseover" in the (1) smile_url or (2) smile_emotion parameters, which bypasses a check for "<" and ">" characters. • http://lists.grok.org.uk/pipermail/full-disclosure/2006-February/041920.html http://secunia.com/advisories/18693 http://securityreason.com/achievement_securityalert/31 http://securityreason.com/securityalert/406 http://www.osvdb.org/22928 http://www.vupen.com/english/advisories/2006/0445 https://exchange.xforce.ibmcloud.com/vulnerabilities/24497 •

CVSS: 5.0EPSS: 4%CPEs: 29EXPL: 1

Cross-site request forgery (CSRF) vulnerability in phpBB 2.0.19, when Link to off-site Avatar or bbcode (IMG) are enabled, allows remote attackers to perform unauthorized actions as a logged in user via a link or IMG tag in a user profile, as demonstrated using links to (1) admin/admin_users.php and (2) modcp.php. • http://lists.grok.org.uk/pipermail/full-disclosure/2006-February/041920.html http://secunia.com/advisories/18693 http://securityreason.com/achievement_securityalert/31 http://securityreason.com/securityalert/406 http://www.osvdb.org/22929 http://www.vupen.com/english/advisories/2006/0445 https://exchange.xforce.ibmcloud.com/vulnerabilities/24497 •