Ubbcentral / Ubb.threads
20 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2012-5104 | Cross-site scripting (XSS) vulnerability in forums/ubbthreads.php in UBB.threads 7.5.6 and earlier allows remote attackers to inject arbitrary web script or HT… | MEDIUM | 4.3 | Sep 23, 2012 |
| CVE-2008-6970 | SQL injection vulnerability in dosearch.inc.php in UBB.threads 7.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the Forum[] arra… | HIGH | 7.5 | Aug 13, 2009 |
| CVE-2007-1956 | SQL injection vulnerability in ubbthreads.php in Groupee UBB.threads 6.1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the C para… | HIGH | 7.5 | Apr 11, 2007 |
| CVE-2006-5138 | Groupee UBB.threads 6.5.1.1 allows remote attackers to obtain sensitive information via a direct request for cron/php/subscriptions.php, which reveals the path… | MEDIUM | 5.0 | Oct 2, 2006 |
| CVE-2006-5137 | Multiple direct static code injection vulnerabilities in Groupee UBB.threads 6.5.1.1 allow remote attackers to (1) inject PHP code via a theme[] array paramete… | MEDIUM | 5.1 | Oct 2, 2006 |
| CVE-2006-5136 | Multiple PHP remote file inclusion vulnerabilities in ubbt.inc.php in Groupee UBB.threads 6.5.1.1 allow remote attackers to execute arbitrary PHP code via a UR… | HIGH | 7.5 | Oct 2, 2006 |
| CVE-2006-2755 | Cross-site scripting (XSS) vulnerability in index.php in UBBThreads 5.x and earlier allows remote attackers to inject arbitrary web script or HTML via the debu… | MEDIUM | 4.3 | Jun 2, 2006 |
| CVE-2006-2675 | PHP remote file inclusion vulnerability in ubbt.inc.php in UBBThreads 5.x and 6.x allows remote attackers to execute arbitrary PHP code via a URL in the (1) th… | MEDIUM | 5.1 | May 30, 2006 |
| CVE-2006-2568 | PHP remote file inclusion vulnerability in addpost_newpoll.php in UBB.threads 6.4 through 6.5.2 and 6.5.1.1 (trial) allows remote attackers to execute arbitrar… | MEDIUM | 5.1 | May 24, 2006 |
| CVE-2006-1423 | SQL injection vulnerability in showflat.php in UBB.threads 5.5.1, 6.0 br5, 6.0.1, 6.0.2, and earlier, allows remote attackers to execute arbitrary SQL commands… | MEDIUM | 5.0 | Mar 28, 2006 |
| CVE-2006-0545 | SQL injection vulnerability in showflat.php in Groupee (formerly known as Infopop) UBB.threads 6.3 and earlier allows remote attackers to execute arbitrary SQL… | HIGH | 7.5 | Feb 4, 2006 |
| CVE-2004-2510 | Cross-site scripting (XSS) vulnerability in showflat.php in Infopop UBB.Threads before 6.5 allows remote attackers to inject arbitrary web script or HTML via t… | MEDIUM | 4.3 | Oct 25, 2005 |
| CVE-2004-2509 | Cross-site scripting (XSS) vulnerabilities in (1) calendar.php, (2) login.php, and (3) online.php in Infopop UBB.Threads 6.2.3 and 6.5 allow remote attackers t… | MEDIUM | 4.3 | Oct 25, 2005 |
| CVE-2005-2061 | Infopop UBB.Threads before 6.5.2 Beta allows remote attackers to include arbitrary files via the language parameter in a cookie followed by a null (%00) byte. | MEDIUM | 5.0 | Jun 28, 2005 |
| CVE-2005-2060 | Multiple HTTP Response Splitting vulnerabilities in (1) toggleshow.php, (2) togglecats.php, and (3) showprofile.php in Infopop UBB.Threads before 6.5.2 Beta al… | MEDIUM | 5.0 | Jun 28, 2005 |
| CVE-2005-2059 | Multiple cross-site request forgery (CSRF) vulnerabilities in (1) addaddress.php, (2) toggleignore.php, (3) removeignore.php, and (4) removeaddress.php in Info… | MEDIUM | 6.5 | Jun 28, 2005 |
| CVE-2005-2058 | Multiple SQL injection vulnerabilities in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to execute arbitrary SQL commands via the Number paramet… | HIGH | 7.5 | Jun 28, 2005 |
| CVE-2005-2057 | Multiple cross-site scripting (XSS) vulnerabilities in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to inject arbitrary web script or HTML via… | MEDIUM | 6.8 | Jun 28, 2005 |
| CVE-2005-0726 | SQL injection vulnerability in editpost.php in UBB.threads 6.0 allows remote attackers to execute arbitrary SQL commands via the Number parameter. | HIGH | 7.5 | Mar 12, 2005 |
| CVE-2004-1622 | SQL injection vulnerability in dosearch.php in UBB.threads 3.4.x allows remote attackers to execute arbitrary SQL statements via the Name parameter. | HIGH | 7.5 | Feb 20, 2005 |
Showing 1 to 20 of 20 CVEs