VYPR
Vendor

Fluxbb

Products
1
CVEs
3
Across products
3
Status
Private

Products

1

Recent CVEs

3
  • CVE-2014-10029Jan 13, 2015
    risk 0.03cvss epss 0.04

    SQL injection vulnerability in profile.php in FluxBB before 1.4.13 and 1.5.x before 1.5.7 allows remote attackers to execute arbitrary SQL commands via the req_new_email parameter.

  • CVE-2014-9574Feb 3, 2015
    risk 0.00cvss epss 0.01

    Directory traversal vulnerability in install.php in FluxBB before 1.5.8 allows remote attackers to include and execute arbitrary local install.php files via a .. (dot dot) in the install_lang parameter.

  • CVE-2014-10030Jan 13, 2015
    risk 0.00cvss epss 0.00

    Open redirect vulnerability in forums/login.php in FluxBB before 1.4.13 and 1.5.x before 1.5.7 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect_url parameter.