Usebb
Products
1- 12 CVEs
Recent CVEs
12| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-8088 | Cri | 0.64 | 9.8 | 0.01 | Jan 27, 2020 | panel_login.php in UseBB 1.0.12 allows type juggling for login bypass because != is used instead of !== for password hashes, which mishandles hashes that begin with 0e followed by exclusively numerical characters. | ||
| CVE-2011-3612 | Hig | 0.57 | 8.8 | 0.01 | Jan 22, 2020 | Cross-Site Request Forgery (CSRF) vulnerability exists in panel.php in UseBB before 1.0.12. | ||
| CVE-2011-3611 | Hig | 0.47 | 7.2 | 0.03 | Jan 22, 2020 | A File Inclusion vulnerability exists in act parameter to admin.php in UseBB before 1.0.12. | ||
| CVE-2007-3963 | 0.03 | — | 0.02 | Jul 25, 2007 | Multiple cross-site scripting (XSS) vulnerabilities in UseBB 1.0.7, and possibly other 1.0.x versions, allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF) to (1) upgrade-0-2-3.php, (2) upgrade-0-3.php, or (3) upgrade-0-4.php in install/, a… | |||
| CVE-2010-3713 | 0.00 | — | 0.01 | Oct 28, 2010 | rss.php in UseBB before 1.0.11 does not properly handle forum configurations in which a user has the view permission but not the read permission, which allows remote attackers to bypass intended access restrictions by reading a forum feed in combination with a topic feed. | |||
| CVE-2009-4041 | 0.00 | — | 0.02 | Nov 20, 2009 | UseBB 1.0.9 before 1.0.10 allows remote attackers to cause a denial of service (infinite loop) via crafted BBCode tags. | |||
| CVE-2007-2066 | 0.00 | — | 0.01 | Apr 18, 2007 | UseBB before 1.0.6 allows remote attackers to obtain sensitive information via a request with unspecified GET or POST parameters to an unspecified script, which reveals the path in an error message. | |||
| CVE-2006-2524 | 0.00 | — | 0.01 | May 22, 2006 | Cross-site scripting (XSS) vulnerability in UseBB 1.0 RC1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors when processing the user date format. | |||
| CVE-2006-2525 | 0.00 | — | 0.01 | May 22, 2006 | SQL injection vulnerability in UseBB 1.0 RC1 and earlier allows remote attackers to execute arbitrary SQL commands via the member list search module. | |||
| CVE-2005-4193 | 0.00 | — | 0.01 | Dec 13, 2005 | Cross-site scripting (XSS) vulnerability in UseBB before 0.7 allows remote attackers to inject arbitrary web script or HTML via the $_SERVER['PHP_SELF'] variable. | |||
| CVE-2005-2438 | 0.00 | — | 0.01 | Aug 3, 2005 | Cross-site scripting (XSS) vulnerability in UseBB 0.5.1 and earlier allows remote attackers to inject arbitrary Javascript via the BBCode color value. | |||
| CVE-2005-2439 | 0.00 | — | 0.01 | Aug 3, 2005 | SQL injection vulnerability in UseBB 0.5.1 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the search function. |
- risk 0.64cvss 9.8epss 0.01
panel_login.php in UseBB 1.0.12 allows type juggling for login bypass because != is used instead of !== for password hashes, which mishandles hashes that begin with 0e followed by exclusively numerical characters.
- risk 0.57cvss 8.8epss 0.01
Cross-Site Request Forgery (CSRF) vulnerability exists in panel.php in UseBB before 1.0.12.
- risk 0.47cvss 7.2epss 0.03
A File Inclusion vulnerability exists in act parameter to admin.php in UseBB before 1.0.12.
- CVE-2007-3963Jul 25, 2007risk 0.03cvss —epss 0.02
Multiple cross-site scripting (XSS) vulnerabilities in UseBB 1.0.7, and possibly other 1.0.x versions, allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF) to (1) upgrade-0-2-3.php, (2) upgrade-0-3.php, or (3) upgrade-0-4.php in install/, a…
- CVE-2010-3713Oct 28, 2010risk 0.00cvss —epss 0.01
rss.php in UseBB before 1.0.11 does not properly handle forum configurations in which a user has the view permission but not the read permission, which allows remote attackers to bypass intended access restrictions by reading a forum feed in combination with a topic feed.
- CVE-2009-4041Nov 20, 2009risk 0.00cvss —epss 0.02
UseBB 1.0.9 before 1.0.10 allows remote attackers to cause a denial of service (infinite loop) via crafted BBCode tags.
- CVE-2007-2066Apr 18, 2007risk 0.00cvss —epss 0.01
UseBB before 1.0.6 allows remote attackers to obtain sensitive information via a request with unspecified GET or POST parameters to an unspecified script, which reveals the path in an error message.
- CVE-2006-2524May 22, 2006risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in UseBB 1.0 RC1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors when processing the user date format.
- CVE-2006-2525May 22, 2006risk 0.00cvss —epss 0.01
SQL injection vulnerability in UseBB 1.0 RC1 and earlier allows remote attackers to execute arbitrary SQL commands via the member list search module.
- CVE-2005-4193Dec 13, 2005risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in UseBB before 0.7 allows remote attackers to inject arbitrary web script or HTML via the $_SERVER['PHP_SELF'] variable.
- CVE-2005-2438Aug 3, 2005risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in UseBB 0.5.1 and earlier allows remote attackers to inject arbitrary Javascript via the BBCode color value.
- CVE-2005-2439Aug 3, 2005risk 0.00cvss —epss 0.01
SQL injection vulnerability in UseBB 0.5.1 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the search function.