VYPR
Vendor

Usebb

Products
1
CVEs
9
Across products
9
Status
Private

Products

1

Recent CVEs

9
  • CVE-2007-3963Jul 25, 2007
    risk 0.03cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in UseBB 1.0.7, and possibly other 1.0.x versions, allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF) to (1) upgrade-0-2-3.php, (2) upgrade-0-3.php, or (3) upgrade-0-4.php in install/, a different vulnerability than CVE-2005-4193.

  • CVE-2011-3612Jan 22, 2020
    risk 0.00cvss epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability exists in panel.php in UseBB before 1.0.12.

  • CVE-2011-3611Jan 22, 2020
    risk 0.00cvss epss 0.02

    A File Inclusion vulnerability exists in act parameter to admin.php in UseBB before 1.0.12.

  • CVE-2010-3713Oct 28, 2010
    risk 0.00cvss epss 0.00

    rss.php in UseBB before 1.0.11 does not properly handle forum configurations in which a user has the view permission but not the read permission, which allows remote attackers to bypass intended access restrictions by reading a forum feed in combination with a topic feed.

  • CVE-2009-4041Nov 20, 2009
    risk 0.00cvss epss 0.01

    UseBB 1.0.9 before 1.0.10 allows remote attackers to cause a denial of service (infinite loop) via crafted BBCode tags.

  • CVE-2007-2066Apr 18, 2007
    risk 0.00cvss epss 0.00

    UseBB before 1.0.6 allows remote attackers to obtain sensitive information via a request with unspecified GET or POST parameters to an unspecified script, which reveals the path in an error message.

  • CVE-2006-2525May 22, 2006
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in UseBB 1.0 RC1 and earlier allows remote attackers to execute arbitrary SQL commands via the member list search module.

  • CVE-2006-2524May 22, 2006
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in UseBB 1.0 RC1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors when processing the user date format.

  • CVE-2005-2439Aug 3, 2005
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in UseBB 0.5.1 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the search function.