Vulnerabilities
Vulnerable Software
Punbb:  >> Punbb  >> 1.0_beta1a  Security Vulnerabilities
SQL injection vulnerability in search.php in PunBB before 1.2.14, when the PHP installation is vulnerable to CVE-2006-3017, allows remote attackers to execute arbitrary SQL commands via the result_list array parameter, which is not initialized.
CVSS Score
5.1
EPSS Score
0.008
Published
2006-11-06
Multiple SQL injection vulnerabilities in PunBB before 1.2.14 allow remote authenticated administrators to execute arbitrary SQL commands via unspecified vectors.
CVSS Score
7.2
EPSS Score
0.002
Published
2006-11-06
Cross-site scripting (XSS) vulnerability in header.php in PunBB 1.2.10 allows remote attackers to inject arbitrary web script or HTML via the URL, which is not properly handled when the PHP_SELF variable is used to handle a pun_page tag.
CVSS Score
4.3
EPSS Score
0.005
Published
2006-03-09
PunBB 1.2.10 and earlier allows remote attackers to cause a denial of service (resource consumption) by registering many user accounts quickly.
CVSS Score
5.0
EPSS Score
0.038
Published
2006-02-23
PunBB 1.2.10 and earlier allows remote attackers to conduct brute force guessing attacks for an account's password, which may be as short as 4 characters.
CVSS Score
5.0
EPSS Score
0.004
Published
2006-02-23
Cross-site scripting (XSS) vulnerability in PunBB before 1.2.8 allows remote attackers to inject arbitrary web script or HTML via the "forgotten e-mail" feature.
CVSS Score
4.3
EPSS Score
0.003
Published
2005-09-27
PunBB before 1.2.8 allows remote attackers to perform "code inclusion" via the user language selection.
CVSS Score
4.6
EPSS Score
0.005
Published
2005-09-27


Contact Us

Shodan ® - All rights reserved