Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 310 respecto a la semana anterior
Críticas / altas1351▲ 96 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
199 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.3% | — | Phpbb Group Phpbb | 10/10/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in admin/admin_topic_action_logging.php in Admin Topic Action Logging Mod 0.95 and earlier, as used in phpBB 2.0 up to 2.0.21, allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | |
| Modificada | Media (5.1) | 3.1% | — | Phpbb XS | 29/9/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in includes/functions_kb.php in the phpBB XS 2 (Spain version) allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter, a different vector than CVE-2006-4780 or CVE-2006-4893. | |
| Modificada | Alta (7.5) | 2.2% | — | Phpbb Security Importal | 29/9/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in includes/functions_portal.php in Integrated MODs (IM) Portal 1.2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | |
| Modificada | Alta (7.5) | 9.7% | — | Postnuke Software Foundation Pnphpbb | 25/9/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in includes/functions_admin.php in PNphpBB 1.2g allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | |
| Modificada | Alta (7.5) | 3.1% | — | Phpbb XS | 19/9/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in bb_usage_stats/includes/bb_usage_stats.php in phpBB XS 0.58 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter, a different vector than CVE-2006-4780. | |
| Modificada | Alta (7.5) | 8.7% | — | Phpbbxs Phpbb XS | 14/9/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in includes/functions.php in phpBB XS 0.58 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | |
| Modificada | Alta (7.5) | 2.9% | — | Phpbb Group Vitrax Premodded Phpbb | 14/9/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in includes/functions_portal.php in Vitrax Premodded phpBB 1.0.6-R3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | |
| Modificada | Media (4.6) | 1.6% | — | Phpbb Group Phpbb | 13/9/2006 | 16/6/2026 | phpBB 2.0.21 does not properly handle pathnames ending in %00, which allows remote authenticated administrative users to upload arbitrary files, as demonstrated by a query to admin/admin_board.php with an avatar_path parameter ending in .php%00. | |
| Modificada | Media (5.1) | 4.2% | — | Phpbb Group Phpbb | 30/8/2006 | 16/6/2026 | usercp_avatar.php in PHPBB 2.0.20, when avatar uploading is enabled, allows remote attackers to use the server as a web proxy by submitting a URL to the avatarurl parameter, which is then used in an HTTP GET request. | |
| Modificada | Alta (7.5) | 1.1% | — | Phpbb Group Phpbb-auction | 31/7/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in phpbb-Auction allow remote attackers to execute arbitrary SQL commands via (1) the ar parameter in auction_room.php and (2) the u parameter in auction_store.php. NOTE: the auction_rating.php vector is already covered by CVE-2005-1234. NOTE: the original disclosure states that… | |
| Modificada | Alta (7.5) | 2.8% | — | Phpbb Group Phpbb | 6/6/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in template.php in phpBB 2 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. NOTE: followup posts have disputed this issue, stating that template.php does not appear in phpBB and does not use a $page variable. It is possible that this is a… | |
| Modificada | Media (5.1) | 4.4% | — | Phpbb-portal Blend Portal | 1/6/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in blend_data/blend_common.php in Blend Portal 1.2.0, as used with phpBB when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. NOTE: This is a similar vulnerability to CVE-2006-2507. | |
| Modificada | Alta (7.5) | 1.1% | — | Phpbb Group Phpbb | 15/5/2006 | 16/6/2026 | SQL injection vulnerability in charts.php in the Chart mod for phpBB allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (4.3) | 1.00% | — | Phpbb Group Phpbb | 15/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in charts.php in the Chart mod for phpBB allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: this issue might be resultant from SQL injection. | |
| Modificada | Media (6.8) | 7.6% | — | Phpbb Group Phpbb-auction | 9/5/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in auction\auction_common.php in Auction mod 1.3m for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | |
| Modificada | Media (6.4) | 2.0% | — | Phpbb Group Phpbb Toplist | 3/5/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in top/list.php in phpBB TopList 1.3.8 and earlier allows remote attackers to include arbitrary files via the returnpath parameter. | |
| Modificada | Alta (7.5) | 8.3% | — | Phpbb Group Phpbb Advanced Guestbook | 3/5/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in admin/addentry.php in phpBB Advanced Guestbook 2.4.0 and earlier, when register_globals is enabled, allows remote attackers to include arbitrary files via the phpbb_root_path parameter. | |
| Modificada | Alta (7.5) | 11% | — | Phpbb Group Phpbb Toplist | 3/5/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in toplist.php in phpBB TopList 1.3.8 and earlier, when register_globals is enabled, allows remote attackers to include arbitrary files via the phpbb_root_path parameter. | |
| Modificada | Media (5.1) | 9.5% | — | Phpbb Group Phpbb | 2/5/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in /includes/kb_constants.php in Knowledge Base Mod for PHPbb 2.0.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter. | |
| Modificada | Media (6) | 1.3% | — | Phpbb Group Phpbb | 20/4/2006 | 16/6/2026 | Unspecified vulnerability in phpBB allows remote authenticated users with Administration Panel access to execute arbitrary PHP code via crafted Font Colour 3 ($theme[fontcolor3] variable) and/or signature values, possibly involving the highlight functionality. NOTE: the original report does not clarify whether this… | |
| Modificada | Media (6.5) | 1.4% | — | Phpbb Group Phpbb | 20/4/2006 | 16/6/2026 | Direct static code injection vulnerability in includes/template.php in phpBB allows remote authenticated users with write access to execute arbitrary PHP code by modifying a template in a way that (1) bypasses a loose ".*" regular expression to match BEGIN and END statements in overall_header.tpl, or (2) is used in an… | |
| Modificada | Media (4.3) | 1.2% | — | Phpbb Group Phpbb | 13/4/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in phpBB 2.0.19 allow remote attackers to inject arbitrary web script or HTML via the (1) Site Description field in (a) admin_board.php, the (2) Group name and (3) Group description fields in (b) admin_groups.php and (c) groupcp.php, the (4) Theme Name field in (d)… | |
| Modificada | Media (4.3) | 1.4% | — | Phpbb Group Phpbb | 4/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in profile.php in phpBB 2.0.19 allows remote attackers to inject arbitrary web script or HTML via the cur_password parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (6.4) | 2.6% | — | Phpbb Group Phpbb | 10/2/2006 | 16/6/2026 | The gen_rand_string function in phpBB 2.0.19 uses insufficiently random data (small value space) to create the activation key ("validation ID") that is sent by e-mail when establishing a password, which makes it easier for remote attackers to obtain the key and modify passwords for existing accounts or create new… | |
| Modificada | Media (5) | 2.5% | — | Phpbb Group Phpbb | 6/2/2006 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in phpBB 2.0.19, when Link to off-site Avatar or bbcode (IMG) are enabled, allows remote attackers to perform unauthorized actions as a logged in user via a link or IMG tag in a user profile, as demonstrated using links to (1) admin/admin_users.php and (2) modcp.php. |