Search Results (64 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2017-1000419 1 Phpbb 1 Phpbb 2024-11-21 N/A
phpBB version 3.2.0 is vulnerable to SSRF in the Remote Avatar function resulting allowing an attacker to perform port scanning, requesting internal content and potentially attacking such internal services via the web application.
CVE-2010-1630 1 Phpbb 1 Phpbb 2024-08-07 N/A
Unspecified vulnerability in posting.php in phpBB before 3.0.5 has unknown impact and attack vectors related to the use of a "forum id" in circumstances related to a "global announcement."
CVE-2010-1627 1 Phpbb 1 Phpbb 2024-08-07 N/A
feed.php in phpBB 3.0.7 before 3.0.7-PL1 does not properly check permissions for feeds, which allows remote attackers to bypass intended access restrictions via unspecified attack vectors related to permission settings on a private forum.
CVE-2011-0544 2 Debian, Phpbb 2 Debian Linux, Phpbb 2024-08-06 6.1 Medium
phpbb 3.0.x-3.0.6 has an XSS vulnerability via the [flash] BB tag.