Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
205 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.2% | — | Mybulletinboard | 1/8/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in usercp.php in MyBB (aka MyBulletinBoard) 1.x allows remote attackers to inject arbitrary web script or HTML via the gallery parameter. | |
| Modificada | Media (5) | 1.7% | — | Mybulletinboard | 1/8/2006 | 16/6/2026 | Directory traversal vulnerability in usercp.php in MyBB (aka MyBulletinBoard) 1.x allows remote attackers to read arbitrary files via a .. (dot dot) in the gallery parameter in a (1) avatar or (2) do_avatar action. | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Mybulletinboard | 24/7/2006 | 16/6/2026 | SQL injection vulnerability in the init function in class_session.php in MyBB (aka MyBulletinBoard) 1.1.5 allows remote attackers to execute arbitrary SQL commands via the CLIENT-IP HTTP header ($_SERVER['HTTP_CLIENT_IP'] variable), as utilized by index.php. | |
| Modificada | Alta (7.5) | 1.2% | — | Mybulletinboard | 21/7/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in MyBB (aka MyBulletinBoard) 1.1.4 allow remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (5) | 1.2% | — | Mybulletinboard | 21/7/2006 | 16/6/2026 | Unspecified vulnerability in MyBB (aka MyBulletinBoard) 1.1.4, related has unspecified impact and attack vectors related to "user group manipulation." | |
| Modificada | Media (4.3) | 2.6% | — | Mybulletinboard | 21/7/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in inc/functions_post.php in MyBB (aka MyBulletinBoard) 1.0 RC2 through 1.1.4 allows remote attackers to inject arbitrary web script or HTML via a javascript URI with an SGML numeric character reference in the url BBCode tag, as demonstrated using "javascript". | |
| Modificada | Alta (7.5) | 1.3% | — | Mybulletinboard | 21/7/2006 | 16/6/2026 | inc/init.php in Archive Mode (Light) in MyBB (aka MyBulletinBoard) 1.1.4 calls the extract function with EXTR_OVERWRITE on HTTP POST and GET variables, which allows remote attackers to overwrite arbitrary variables, as demonstrated via an SQL injection using the _SERVER[HTTP_CLIENT_IP] parameter in archive/index.php. | |
| Modificada | Alta (7.5) | 1.5% | — | Mybulletinboard | 7/7/2006 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in editpost.php in MyBulletinBoard (MyBB) before 1.1.5 allows remote attackers to perform unauthorized actions as a logged in user and delete arbitrary forum posts via a bbcode IMG tag with a modified delete parameter in a deletepost action. NOTE: the provenance of this… | |
| Modificada | Baja (2.6) | 2.0% | 💥 Exploit | Jelsoft Vbulletin | 28/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in member.php in vBulletin 3.5.x allows remote attackers to inject arbitrary web script or HTML via the u parameter. NOTE: the vendor has disputed this report, stating that they have been unable to replicate the issue and that "the userid parameter is run through our filtering… | |
| Modificada | Alta (7.5) | 1.4% | — | Mybulletinboard | 27/6/2006 | 16/6/2026 | SQL injection vulnerability in usercp.php in MyBB (MyBulletinBoard) 1.0 through 1.1.3 allows remote attackers to execute arbitrary SQL commands via the showcodebuttons parameter. | |
| Modificada | Alta (7.5) | 4.4% | 💥 Exploit | Mybulletinboard | 13/6/2006 | 16/6/2026 | The domecode function in inc/functions_post.php in MyBulletinBoard (MyBB) 1.1.2, and possibly other versions, allows remote attackers to execute arbitrary PHP code via the username field, which is used in a preg_replace function call with a /e (executable) modifier. | |
| Modificada | Media (6.8) | 2.0% | — | Mybulletinboard | 12/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in private.php in MyBB 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the do parameter. | |
| Modificada | Media (5) | 0.88% | 💥 Exploit | Jelsoft Vbulletin | 3/6/2006 | 16/6/2026 | SQL injection vulnerability in VBulletin 3.0.10 allows remote attackers to execute arbitrary SQL commands via the featureid parameter. | |
| Modificada | Media (6.4) | 1.1% | — | Mybulletinboard | 25/5/2006 | 16/6/2026 | SQL injection vulnerability in rss.php in MyBB (aka MyBulletinBoard) 1.1.1 allows remote attackers to execute arbitrary SQL commands via the comma parameter. NOTE: it is not clear from the original report how this attack can succeed, since the demonstration URL uses a variable that is overwritten with static data in… | |
| Modificada | Media (6.4) | 1.1% | 💥 Exploit | Mybulletinboard | 12/5/2006 | 16/6/2026 | SQL injection vulnerability in showthread.php in MyBB (aka MyBulletinBoard) 1.1.1 allows remote attackers to execute arbitrary SQL commands via the comma parameter. | |
| Modificada | Media (6.4) | 1.2% | — | Mybulletinboard | 12/5/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in MyBB (aka MyBulletinBoard) 1.1.1 allow remote attackers to execute arbitrary SQL commands via the e-mail address when registering for a forum that requires e-mail verification, which is not properly handled in (1) usercp.php and (2) member.php. | |
| Modificada | Media (6.5) | 3.4% | — | Jelsoft Vbulletin | 12/5/2006 | 16/6/2026 | Jelsoft vBulletin accepts uploads of Cascading Style Sheets (CSS) and processes them in a way that allows remote authenticated administrators to gain shell access by uploading a CSS file that contains PHP code, then selecting the file via the style chooser, which causes the PHP code to be executed. NOTE: the vendor… | |
| Modificada | Media (5) | 1.4% | — | Devsyn Open Bulletin Board | 5/5/2006 | 16/6/2026 | Open Bulletin Board (OpenBB) 1.0.8 allows remote attackers to obtain the full path of the web server via an invalid pforums parameter to (1) misc.php and (2) member.php. | |
| Modificada | Media (4.3) | 1.1% | — | Devsyn Open Bulletin Board | 29/4/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Devsyn Open Bulletin Board (OpenBB) 1.0.6 allow remote attackers to inject arbitrary web script or HTML via (1) the FID parameter in board.php and (2) the TID parameter in read.php. NOTE: the SQL injection issues are already covered by CVE-2005-1612 (read.php) and… | |
| Modificada | Baja (2.1) | 1.00% | — | Mybulletinboard | 29/4/2006 | 16/6/2026 | SQL injection vulnerability in MyBB (MyBulletinBoard) 1.1.1 allows remote authenticated administrators to execute arbitrary SQL commands via the (1) query string ($querystring variable) in (a) admin/adminlogs.php, which is not properly handled by adminfunctions.php; or (2) setid, (3) expand, (4) title, or (5) sid2… | |
| Modificada | Alta (7.5) | 1.2% | — | Jelsoft Vbulletin | 25/4/2006 | 16/6/2026 | SQL injection vulnerability in calendar.php in vBulletin 3.0.x allows remote attackers to execute arbitrary SQL commands via the eventid parameter. NOTE: the affected version has been disputed by the vendor. It appears that this is the same issue as CVE-2004-0036, which was fixed in 2.3.4. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Mybulletinboard | 21/4/2006 | 16/6/2026 | SQL injection vulnerability in index.php in MyBB (MyBulletinBoard) before 1.04 allows remote attackers to execute arbitrary SQL commands via the referrer parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Mybulletinboard | 20/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in MyBB (MyBulletinBoard) 1.1 allows remote attackers to inject arbitrary web script or HTML via the attachment content disposition in an HTML attachment. | |
| Modificada | Media (5.8) | 1.6% | 💥 Exploit | Mybulletinboard | 20/4/2006 | 16/6/2026 | MyBB (MyBulletinBoard) 1.1.0 does not set the constant KILL_GLOBAL variable in (1) global.php and (2) inc/init.php, which allows remote attackers to initialize arbitrary variables that are processed by an @extract command, which could then be leveraged to conduct cross-site scripting (XSS) or SQL injection attacks. | |
| Modificada | Media (5) | 2.9% | — | Jelsoft Vbulletin | 18/4/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in VBulletin 3.5.1, 3.5.2, and 3.5.4 allows remote attackers to execute arbitrary code via a URL in the systempath parameter to (1) ImpExModule.php, (2) ImpExController.php, and (3) ImpExDisplay.php. |