CVE-2005-4665
https://notcve.org/view.php?id=CVE-2005-4665
Cross-site scripting (XSS) vulnerability in PunBB 1.2.6 and earlier allows remote attackers to inject arbitrary web script or HTML via Javascript contained in nested, malformed BBcode url tags. • http://punbb.org/changelogs/1.2.6_to_1.2.7.txt http://secunia.com/advisories/16775 http://www.osvdb.org/19382 http://www.punbb.org/changelogs/1.2.6_to_1.2.7.txt http://www.securityfocus.com/archive/1/422088/100/0/threaded http://www.securityfocus.com/archive/1/422267/100/0/threaded http://www.securityfocus.com/bid/14808 http://www.vupen.com/english/advisories/2005/1708 https://exchange.xforce.ibmcloud.com/vulnerabilities/22234 •
CVE-2005-4686
https://notcve.org/view.php?id=CVE-2005-4686
PunBB 1.2.9, when used alone or with F-ART BLOG:CMS, includes config.php before calling the unregister_globals function, which allows attackers to obtain unspecified sensitive information. • http://secunia.com/advisories/17425 http://secunia.com/advisories/17433 http://www.punbb.org/changelogs/1.2.9_to_1.2.10.txt http://www.securityfocus.com/bid/15328 •
CVE-2005-3518 – PunBB 1.2.x - 'search.php' SQL Injection
https://notcve.org/view.php?id=CVE-2005-3518
SQL injection vulnerability in search.php in PunBB 1.2.7 and 1.2.8 allows remote attackers to execute arbitrary SQL commands via the old_searches parameter. • https://www.exploit-db.com/exploits/26350 http://marc.info/?l=bugtraq&m=112939699128430&w=2 http://secunia.com/advisories/17227 http://securityreason.com/securityalert/87 http://www.kapda.ir/advisory-91.html http://www.osvdb.org/20018 http://www.punbb.org/changelogs/1.2.8_to_1.2.9.txt http://www.securityfocus.net/bid/15114 https://exchange.xforce.ibmcloud.com/vulnerabilities/22760 •
CVE-2005-3328
https://notcve.org/view.php?id=CVE-2005-3328
PHP remote file inclusion vulnerability in common.php in PunBB 1.1.2 through 1.1.5 allows remote attackers to execute arbitrary code via the pun_root parameter. • http://marc.info/?l=bugtraq&m=113017630505223&w=2 http://securityreason.com/securityalert/107 http://www.securityfocus.com/bid/15175 •
CVE-2005-3078
https://notcve.org/view.php?id=CVE-2005-3078
Cross-site scripting (XSS) vulnerability in PunBB before 1.2.8 allows remote attackers to inject arbitrary web script or HTML via the "forgotten e-mail" feature. • http://secunia.com/advisories/16908 http://www.punbb.org/changelogs/1.2.7_to_1.2.8.txt •