Vulnerabilities
Vulnerable Software
Usebb:  >> Usebb  >> 0.5.1  Security Vulnerabilities
Cross-Site Request Forgery (CSRF) vulnerability exists in panel.php in UseBB before 1.0.12.
CVSS Score
8.8
EPSS Score
0.004
Published
2020-01-22
A File Inclusion vulnerability exists in act parameter to admin.php in UseBB before 1.0.12.
CVSS Score
7.2
EPSS Score
0.02
Published
2020-01-22
rss.php in UseBB before 1.0.11 does not properly handle forum configurations in which a user has the view permission but not the read permission, which allows remote attackers to bypass intended access restrictions by reading a forum feed in combination with a topic feed.
CVSS Score
4.3
EPSS Score
0.002
Published
2010-10-28
Cross-site scripting (XSS) vulnerability in UseBB before 0.7 allows remote attackers to inject arbitrary web script or HTML via the $_SERVER['PHP_SELF'] variable.
CVSS Score
4.3
EPSS Score
0.004
Published
2005-12-13
Cross-site scripting (XSS) vulnerability in UseBB 0.5.1 and earlier allows remote attackers to inject arbitrary Javascript via the BBCode color value.
CVSS Score
4.3
EPSS Score
0.006
Published
2005-08-03
SQL injection vulnerability in UseBB 0.5.1 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the search function.
CVSS Score
7.5
EPSS Score
0.006
Published
2005-08-03


Contact Us

Shodan ® - All rights reserved