Vulnerabilities
Vulnerable Software
Usebb:  >> Usebb  >> 1.0.1  Security Vulnerabilities
Cross-Site Request Forgery (CSRF) vulnerability exists in panel.php in UseBB before 1.0.12.
CVSS Score
8.8
EPSS Score
0.004
Published
2020-01-22
A File Inclusion vulnerability exists in act parameter to admin.php in UseBB before 1.0.12.
CVSS Score
7.2
EPSS Score
0.02
Published
2020-01-22
rss.php in UseBB before 1.0.11 does not properly handle forum configurations in which a user has the view permission but not the read permission, which allows remote attackers to bypass intended access restrictions by reading a forum feed in combination with a topic feed.
CVSS Score
4.3
EPSS Score
0.002
Published
2010-10-28
Multiple cross-site scripting (XSS) vulnerabilities in UseBB 1.0.7, and possibly other 1.0.x versions, allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF) to (1) upgrade-0-2-3.php, (2) upgrade-0-3.php, or (3) upgrade-0-4.php in install/, a different vulnerability than CVE-2005-4193.
CVSS Score
9.3
EPSS Score
0.014
Published
2007-07-25
UseBB before 1.0.6 allows remote attackers to obtain sensitive information via a request with unspecified GET or POST parameters to an unspecified script, which reveals the path in an error message.
CVSS Score
5.0
EPSS Score
0.003
Published
2007-04-18


Contact Us

Shodan ® - All rights reserved