<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – phpBB (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/phpbb.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/phpbb-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – phpBB (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:52 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-29199 – phpBB before 3.3.16 is vulnerable to Host Header Injection that can lead to pass...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-29199</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-29199</guid>
    <pubDate>Mon, 04 May 2026 07:15:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-29199</strong></p>
  <p>phpBB before 3.3.16 is vulnerable to Host Header Injection that can lead to password rest link poisoning. When force_server_vars is disabled, the servers hostname may be extracted from the HTTP Host header which is used to generate the password reset link URL. An attacker who can manipulate the Host header (e.g. through misconfigured host setup or missing header validation by the webserver) can c…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-29199">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-70810 – Cross Site Request Forgery vulnerability in Phpbb phbb3 v.3.3.15 allows a local ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-70810</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-70810</guid>
    <pubDate>Thu, 09 Apr 2026 15:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-70810</strong></p>
  <p>Cross Site Request Forgery vulnerability in Phpbb phbb3 v.3.3.15 allows a local attacker to execute arbitrary code via the login function and the authentication mechanism</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-70810">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25685 – phpBB contains an arbitrary file upload vulnerability that allows authenticated ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25685</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25685</guid>
    <pubDate>Sun, 05 Apr 2026 21:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25685</strong></p>
  <p>phpBB contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by exploiting the plupload functionality and phar:// stream wrapper. Attackers can upload a crafted zip file containing serialized PHP objects that execute arbitrary code when deserialized through the imagick parameter in attachment settings.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25685">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-32575 – Cross-Site Request Forgery (CSRF) vulnerability in axew3 WP w3all phpBB wp-w3all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-32575</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-32575</guid>
    <pubDate>Wed, 09 Apr 2025 17:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-32575</strong></p>
  <p>Cross-Site Request Forgery (CSRF) vulnerability in axew3 WP w3all phpBB wp-w3all-phpbb-integration allows Reflected XSS.This issue affects WP w3all phpBB: from n/a through <= 2.9.9.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-32575">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-16108 – phpBB 3.2.7 allows adding an arbitrary Cascading Style Sheets (CSS) token sequen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-16108</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-16108</guid>
    <pubDate>Fri, 20 Mar 2020 00:17:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-16108</strong></p>
  <p>phpBB 3.2.7 allows adding an arbitrary Cascading Style Sheets (CSS) token sequence to a page through BBCode.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-16108">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-16993 – In phpBB before 3.1.7-PL1, includes/acp/acp_bbcodes.php has improper verificatio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-16993</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-16993</guid>
    <pubDate>Mon, 30 Sep 2019 12:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-16993</strong></p>
  <p>In phpBB before 3.1.7-PL1, includes/acp/acp_bbcodes.php has improper verification of a CSRF token on the BBCode page in the Administration Control Panel. An actual CSRF attack is possible if an attacker also manages to retrieve the session id of a reauthenticated administrator prior to targeting them.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-16993">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-9826 – The fulltext search component in phpBB before 3.2.6 allows Denial of Service.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-9826</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-9826</guid>
    <pubDate>Thu, 02 May 2019 21:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-9826</strong></p>
  <p>The fulltext search component in phpBB before 3.2.6 allows Denial of Service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-9826">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-19274 – Passing an absolute path to a file_exists check in phpBB before 3.2.4 allows Rem...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-19274</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-19274</guid>
    <pubDate>Sat, 17 Nov 2018 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-19274</strong></p>
  <p>Passing an absolute path to a file_exists check in phpBB before 3.2.4 allows Remote Code Execution through Object Injection by employing Phar deserialization when an attacker has access to the Admin Control Panel with founder permissions.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-19274">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-1000419 – phpBB version 3.2.0 is vulnerable to SSRF in the Remote Avatar function resultin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-1000419</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-1000419</guid>
    <pubDate>Tue, 02 Jan 2018 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-1000419</strong></p>
  <p>phpBB version 3.2.0 is vulnerable to SSRF in the Remote Avatar function resulting allowing an attacker to perform port scanning, requesting internal content and potentially attacking such internal services via the web application.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-1000419">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2010-1630 – Unspecified vulnerability in posting.php in phpBB before 3.0.5 has unknown impac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1630</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1630</guid>
    <pubDate>Wed, 19 May 2010 22:30:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2010-1630</strong></p>
  <p>Unspecified vulnerability in posting.php in phpBB before 3.0.5 has unknown impact and attack vectors related to the use of a "forum id" in circumstances related to a "global announcement."</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1630">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-6377 – PHP remote file inclusion vulnerability in include/global.php in Multi SEO phpBB...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-6377</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-6377</guid>
    <pubDate>Mon, 02 Mar 2009 19:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-6377</strong></p>
  <p>PHP remote file inclusion vulnerability in include/global.php in Multi SEO phpBB 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the pfad parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-6377">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-6314 – SQL injection vulnerability in tag_board.php in the Tag Board module 4.0 and ear...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-6314</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-6314</guid>
    <pubDate>Fri, 27 Feb 2009 11:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-6314</strong></p>
  <p>SQL injection vulnerability in tag_board.php in the Tag Board module 4.0 and earlier for phpBB allows remote attackers to execute arbitrary SQL commands via the id parameter in a delete action.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-6314">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-6301 – SQL injection vulnerability in shoutbox_view.php in the Small ShoutBox module 1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-6301</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-6301</guid>
    <pubDate>Thu, 26 Feb 2009 16:17:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-6301</strong></p>
  <p>SQL injection vulnerability in shoutbox_view.php in the Small ShoutBox module 1.4 for phpBB allows remote attackers to execute arbitrary SQL commands via the id parameter in a delete action.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-6301">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-5585 – Multiple PHP remote file inclusion vulnerabilities in lcxBBportal 0.1 Alpha 2 al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-5585</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-5585</guid>
    <pubDate>Tue, 16 Dec 2008 19:07:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-5585</strong></p>
  <p>Multiple PHP remote file inclusion vulnerabilities in lcxBBportal 0.1 Alpha 2 allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter to (1) portal/includes/portal_block.php and (2) includes/acp/acp_lcxbbportal.php.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-5585">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2008-3224 – Unspecified vulnerability in phpBB before 3.0.1 has unknown impact and attack ve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-3224</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-3224</guid>
    <pubDate>Fri, 18 Jul 2008 16:41:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2008-3224</strong></p>
  <p>Unspecified vulnerability in phpBB before 3.0.1 has unknown impact and attack vectors related to "urls gone through redirect() being used within login_box()."</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-3224">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2008-2481 – PHP remote file inclusion vulnerability in authentication/phpbb3/phpbb3.function...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-2481</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-2481</guid>
    <pubDate>Wed, 28 May 2008 15:32:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2008-2481</strong></p>
  <p>PHP remote file inclusion vulnerability in authentication/phpbb3/phpbb3.functions.php in phpRaider 1.0.7 and 1.0.7a, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the pConfig_auth[phpbb_path] parameter.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-2481">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2008-1766 – Multiple unspecified vulnerabilities in phpBB before 3.0.1 have unknown impact a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-1766</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-1766</guid>
    <pubDate>Sat, 12 Apr 2008 20:05:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2008-1766</strong></p>
  <p>Multiple unspecified vulnerabilities in phpBB before 3.0.1 have unknown impact and attack vectors, related to "two minor security-related bugs."</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-1766">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-1565 – Directory traversal vulnerability in forum/irc/irc.php in the PJIRC 0.5 module f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-1565</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-1565</guid>
    <pubDate>Mon, 31 Mar 2008 22:44:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-1565</strong></p>
  <p>Directory traversal vulnerability in forum/irc/irc.php in the PJIRC 0.5 module for phpBB allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the phpEx parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-1565">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-1512 – Directory traversal vulnerability in admin/admin_xs.php in eXtreme Styles module...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-1512</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-1512</guid>
    <pubDate>Tue, 25 Mar 2008 23:44:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-1512</strong></p>
  <p>Directory traversal vulnerability in admin/admin_xs.php in eXtreme Styles module (XS-Mod) 2.3.1 and 2.4.0 for phpBB allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the phpEx parameter. NOTE: some of these details are obtained from third party information.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-1512">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-1350 – SQL injection vulnerability in kb.php in Fully Modded phpBB (phpbbfm) 80220 allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-1350</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-1350</guid>
    <pubDate>Mon, 17 Mar 2008 16:44:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-1350</strong></p>
  <p>SQL injection vulnerability in kb.php in Fully Modded phpBB (phpbbfm) 80220 allows remote attackers to execute arbitrary SQL commands via the k parameter in an article action.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-1350">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-1305 – SQL injection vulnerability in filebase.php in the Filebase mod for phpBB allows...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-1305</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-1305</guid>
    <pubDate>Wed, 12 Mar 2008 17:44:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-1305</strong></p>
  <p>SQL injection vulnerability in filebase.php in the Filebase mod for phpBB allows remote attackers to execute arbitrary SQL commands via the id parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-1305">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-6223 – SQL injection vulnerability in garage.php in phpBB Garage 1.2.0 Beta3 allows rem...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-6223</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-6223</guid>
    <pubDate>Tue, 04 Dec 2007 17:46:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-6223</strong></p>
  <p>SQL injection vulnerability in garage.php in phpBB Garage 1.2.0 Beta3 allows remote attackers to execute arbitrary SQL commands via the make_id parameter in a search action in browse mode.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-6223">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2007-6088 – PHP remote file inclusion vulnerability in includes/functions_mod_user.php in ph...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-6088</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-6088</guid>
    <pubDate>Thu, 22 Nov 2007 00:46:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2007-6088</strong></p>
  <p>PHP remote file inclusion vulnerability in includes/functions_mod_user.php in phpBBViet 02.03.07 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-6088">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-5688 – Multiple SQL injection vulnerabilities in directory.php in the Multi-Forums (aka...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-5688</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-5688</guid>
    <pubDate>Mon, 29 Oct 2007 19:46:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-5688</strong></p>
  <p>Multiple SQL injection vulnerabilities in directory.php in the Multi-Forums (aka Multi Host Forum Pro) module 1.3.3, for phpBB and Invision Power Board (IPB or IP.Board), allow remote attackers to execute arbitrary SQL commands via the (1) go and (2) cat parameters.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-5688">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-4984 – SQL injection vulnerability in index.php in the Ktauber.com StylesDemo mod for p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-4984</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-4984</guid>
    <pubDate>Wed, 19 Sep 2007 19:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-4984</strong></p>
  <p>SQL injection vulnerability in index.php in the Ktauber.com StylesDemo mod for phpBB 2.0.xx allows remote attackers to execute arbitrary SQL commands via the s parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-4984">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-4653 – SQL injection vulnerability in links.php in the Links MOD 1.2.2 and earlier for ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-4653</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-4653</guid>
    <pubDate>Tue, 04 Sep 2007 22:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-4653</strong></p>
  <p>SQL injection vulnerability in links.php in the Links MOD 1.2.2 and earlier for phpBB 2.0.22 and earlier allows remote attackers to execute arbitrary SQL commands via the start parameter in a search action.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-4653">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2007-3935 – PHP remote file inclusion vulnerability in link_main.php in the SupaNav 1.0.0 mo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-3935</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-3935</guid>
    <pubDate>Sat, 21 Jul 2007 00:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2007-3935</strong></p>
  <p>PHP remote file inclusion vulnerability in link_main.php in the SupaNav 1.0.0 module for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-3935">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-3697 – PHP remote file inclusion vulnerability in phpbb/sendmsg.php in FlashBB 1.1.8 an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-3697</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-3697</guid>
    <pubDate>Wed, 11 Jul 2007 22:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-3697</strong></p>
  <p>PHP remote file inclusion vulnerability in phpbb/sendmsg.php in FlashBB 1.1.8 and earlier allows remote attackers to execute arbitrary code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-3697">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-2257 – PHP remote file inclusion vulnerability in subscp.php in Fully Modded phpBB2 all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-2257</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-2257</guid>
    <pubDate>Wed, 25 Apr 2007 17:19:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-2257</strong></p>
  <p>PHP remote file inclusion vulnerability in subscp.php in Fully Modded phpBB2 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-2257">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-2208 – Multiple PHP remote file inclusion vulnerabilities in Extreme PHPBB2 3.0 Pre Fin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-2208</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-2208</guid>
    <pubDate>Tue, 24 Apr 2007 20:19:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-2208</strong></p>
  <p>Multiple PHP remote file inclusion vulnerabilities in Extreme PHPBB2 3.0 Pre Final allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter to (1) functions.php or (2) functions_portal.php in includes/.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-2208">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-1961 – PHP remote file inclusion vulnerability in mutant_functions.php in the Mutant 0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-1961</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-1961</guid>
    <pubDate>Wed, 11 Apr 2007 10:19:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-1961</strong></p>
  <p>PHP remote file inclusion vulnerability in mutant_functions.php in the Mutant 0.9.2 portal for phpBB 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-1961">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-1839 – Multiple PHP remote file inclusion vulnerabilities in CodeBB 1.1b3 and earlier a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-1839</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-1839</guid>
    <pubDate>Tue, 03 Apr 2007 00:19:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-1839</strong></p>
  <p>Multiple PHP remote file inclusion vulnerabilities in CodeBB 1.1b3 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter to (1) pass_code.php or (2) lang_select.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-1839">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-1818 – PHP remote file inclusion vulnerability in MOD_forum_fields_parse.php in the For...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-1818</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-1818</guid>
    <pubDate>Mon, 02 Apr 2007 23:19:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-1818</strong></p>
  <p>PHP remote file inclusion vulnerability in MOD_forum_fields_parse.php in the Forum picture and META tags 1.7 module for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-1818">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2007-1778 – PHP remote file inclusion vulnerability in db/mysql.php in the Eve-Nuke 0.1 (EN-...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-1778</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-1778</guid>
    <pubDate>Fri, 30 Mar 2007 01:19:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2007-1778</strong></p>
  <p>PHP remote file inclusion vulnerability in db/mysql.php in the Eve-Nuke 0.1 (EN-Forums) module for PHP-Nuke allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-1778">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2007-1695 – PHP remote file inclusion vulnerability in includes/usercp_register.php in phpBB...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-1695</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-1695</guid>
    <pubDate>Tue, 27 Mar 2007 01:19:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2007-1695</strong></p>
  <p>PHP remote file inclusion vulnerability in includes/usercp_register.php in phpBB 2.0.19 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.  NOTE: this issue has been disputed by third-party researchers, stating that the file checks for a global constant and cannot be accessed directly</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-1695">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2006-7174 – PHP remote file inclusion vulnerability in includes/functions.php in the Dimensi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-7174</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-7174</guid>
    <pubDate>Wed, 21 Mar 2007 21:19:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2006-7174</strong></p>
  <p>PHP remote file inclusion vulnerability in includes/functions.php in the Dimension module of phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.  NOTE: this may be the same issue as CVE-2006-5235.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-7174">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-1555 – SQL injection vulnerability in forum.php in the Minerva mod 2.0.21 build 238a an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-1555</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-1555</guid>
    <pubDate>Tue, 20 Mar 2007 22:19:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-1555</strong></p>
  <p>SQL injection vulnerability in forum.php in the Minerva mod 2.0.21 build 238a and earlier for phpBB allows remote attackers to execute arbitrary SQL commands via the c parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-1555">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-7168 – PHP remote file inclusion vulnerability in includes/not_mem.php in the Add Name ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-7168</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-7168</guid>
    <pubDate>Tue, 20 Mar 2007 10:19:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-7168</strong></p>
  <p>PHP remote file inclusion vulnerability in includes/not_mem.php in the Add Name module for PHP allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-7168">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2007-1421 – Multiple PHP remote file inclusion vulnerabilities in Premod SubDog 2 allow remo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-1421</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-1421</guid>
    <pubDate>Tue, 13 Mar 2007 01:19:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2007-1421</strong></p>
  <p>Multiple PHP remote file inclusion vulnerabilities in Premod SubDog 2 allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter to (1) functions_kb.php, (2) themen_portal_mitte.php, or (3) logger_engine.php in includes/.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-1421">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2006-7148 – PHP remote file inclusion vulnerability in includes/bb_usage_stats.php in maluin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-7148</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-7148</guid>
    <pubDate>Wed, 07 Mar 2007 20:19:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2006-7148</strong></p>
  <p>PHP remote file inclusion vulnerability in includes/bb_usage_stats.php in maluinfo 206.2.38 for Brazilian PHPBB allows remote attackers to execute arbitrary PHP code via the phpbb_root_path parameter.  NOTE: this might be the same issues as CVE-2006-4893.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-7148">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2006-7032 – PHP remote file inclusion vulnerability in phpbb/getmsg.php in FlashBB 1.1.5 and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-7032</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-7032</guid>
    <pubDate>Fri, 23 Feb 2007 03:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2006-7032</strong></p>
  <p>PHP remote file inclusion vulnerability in phpbb/getmsg.php in FlashBB 1.1.5 and earlier allows remote attackers to execute arbitrary code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-7032">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-1048 – PHP remote file inclusion vulnerability in admin_rebuild_search.php in phpbb_wor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-1048</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-1048</guid>
    <pubDate>Wed, 21 Feb 2007 17:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-1048</strong></p>
  <p>PHP remote file inclusion vulnerability in admin_rebuild_search.php in phpbb_wordsearch allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-1048">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-0809 – PHP remote file inclusion vulnerability in includes/class_template.php in Catego...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-0809</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-0809</guid>
    <pubDate>Wed, 07 Feb 2007 11:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-0809</strong></p>
  <p>PHP remote file inclusion vulnerability in includes/class_template.php in Categories hierarchy (aka CH or mod-CH) 2.1.2 in ptirhiikmods allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-0809">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-0761 – PHP remote file inclusion vulnerability in config.php in phpBB ezBoard converter...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-0761</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-0761</guid>
    <pubDate>Tue, 06 Feb 2007 02:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-0761</strong></p>
  <p>PHP remote file inclusion vulnerability in config.php in phpBB ezBoard converter (ezconvert) 0.2 allows remote attackers to execute arbitrary PHP code via a URL in the ezconvert_dir parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-0761">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-0762 – PHP remote file inclusion vulnerability in includes/functions.php in phpBB++ Bui...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-0762</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-0762</guid>
    <pubDate>Tue, 06 Feb 2007 02:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-0762</strong></p>
  <p>PHP remote file inclusion vulnerability in includes/functions.php in phpBB++ Build 100 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-0762">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-0680 – PHP remote file inclusion vulnerability in includes/functions.php in Phpbb Tweak...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-0680</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-0680</guid>
    <pubDate>Sat, 03 Feb 2007 01:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-0680</strong></p>
  <p>PHP remote file inclusion vulnerability in includes/functions.php in Phpbb Tweaked 3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-0680">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-0683 – PHP remote file inclusion vulnerability in includes/functions.php in Omegaboard ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-0683</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-0683</guid>
    <pubDate>Sat, 03 Feb 2007 01:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-0683</strong></p>
  <p>PHP remote file inclusion vulnerability in includes/functions.php in Omegaboard 1.0beta4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-0683">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-0684 – PHP remote file inclusion vulnerability in portal.php in Cerulean Portal System ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-0684</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-0684</guid>
    <pubDate>Sat, 03 Feb 2007 01:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-0684</strong></p>
  <p>PHP remote file inclusion vulnerability in portal.php in Cerulean Portal System 0.7b allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-0684">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-0656 – PHP remote file inclusion vulnerability in includes/functions.php in phpBB2-MODi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-0656</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-0656</guid>
    <pubDate>Thu, 01 Feb 2007 22:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-0656</strong></p>
  <p>PHP remote file inclusion vulnerability in includes/functions.php in phpBB2-MODificat 0.2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-0656">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-0662 – PHP remote file inclusion vulnerability in includes/usercp_viewprofile.php in Ha...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-0662</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-0662</guid>
    <pubDate>Thu, 01 Feb 2007 22:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-0662</strong></p>
  <p>PHP remote file inclusion vulnerability in includes/usercp_viewprofile.php in Hailboards 1.2.0 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-0662">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-0591 – PHP remote file inclusion vulnerability in configure.php in Vu Le An Virtual Pat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-0591</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-0591</guid>
    <pubDate>Tue, 30 Jan 2007 18:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-0591</strong></p>
  <p>PHP remote file inclusion vulnerability in configure.php in Vu Le An Virtual Path (VirtualPath) 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-0591">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-0572 – PHP remote file inclusion vulnerability in include/irc/phpIRC.php in Drunken:Gol...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-0572</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-0572</guid>
    <pubDate>Tue, 30 Jan 2007 17:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-0572</strong></p>
  <p>PHP remote file inclusion vulnerability in include/irc/phpIRC.php in Drunken:Golem Gaming Portal 0.5.1 Alpha 2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-0572">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-0581 – PHP remote file inclusion vulnerability in functions.php in EclipseBB 0.5.0 Lite...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-0581</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-0581</guid>
    <pubDate>Tue, 30 Jan 2007 17:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-0581</strong></p>
  <p>PHP remote file inclusion vulnerability in functions.php in EclipseBB 0.5.0 Lite allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-0581">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-0561 – Multiple PHP remote file inclusion vulnerabilities in Xero Portal 1.2 allow remo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-0561</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-0561</guid>
    <pubDate>Tue, 30 Jan 2007 16:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-0561</strong></p>
  <p>Multiple PHP remote file inclusion vulnerabilities in Xero Portal 1.2 allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter to (1) admin_linkdb.php, (2) admin_forum_prune.php, (3) admin_extensions.php, (4) admin_board.php, (5) admin_attachments.php, or (6) admin_users.php in admin/.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-0561">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2006-6839 – Unspecified vulnerability in phpBB before 2.0.22 has unknown impact and remote a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-6839</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-6839</guid>
    <pubDate>Sun, 31 Dec 2006 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2006-6839</strong></p>
  <p>Unspecified vulnerability in phpBB before 2.0.22 has unknown impact and remote attack vectors related to "criteria for 'bad' redirection targets."</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-6839">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2006-6840 – Unspecified vulnerability in phpBB before 2.0.22 has unknown impact and remote a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-6840</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-6840</guid>
    <pubDate>Sun, 31 Dec 2006 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2006-6840</strong></p>
  <p>Unspecified vulnerability in phpBB before 2.0.22 has unknown impact and remote attack vectors related to a "negative start parameter."</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-6840">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2006-6841 – Certain forms in phpBB before 2.0.22 lack session checks, which has unknown impa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-6841</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-6841</guid>
    <pubDate>Sun, 31 Dec 2006 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2006-6841</strong></p>
  <p>Certain forms in phpBB before 2.0.22 lack session checks, which has unknown impact and remote attack vectors.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-6841">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-6789 – PHP remote file inclusion vulnerability in includes/archive/archive_topic.php in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-6789</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-6789</guid>
    <pubDate>Thu, 28 Dec 2006 00:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-6789</strong></p>
  <p>PHP remote file inclusion vulnerability in includes/archive/archive_topic.php in Phpbbxtra 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-6789">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-6593 – PHP remote file inclusion vulnerability in zufallscodepart.php in AMAZONIA MOD f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-6593</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-6593</guid>
    <pubDate>Fri, 15 Dec 2006 19:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-6593</strong></p>
  <p>PHP remote file inclusion vulnerability in zufallscodepart.php in AMAZONIA MOD for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-6593">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-6216 – SQL injection vulnerability in admin_hacks_list.php in the Nivisec Hacks List 1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-6216</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-6216</guid>
    <pubDate>Fri, 01 Dec 2006 01:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-6216</strong></p>
  <p>SQL injection vulnerability in admin_hacks_list.php in the Nivisec Hacks List 1.21 and earlier phpBB module allows remote attackers to execute arbitrary SQL commands via the hack_id parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-6216">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-5665 – PHP remote file inclusion vulnerability in admin/modules_data.php in the phpBB m...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-5665</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-5665</guid>
    <pubDate>Fri, 03 Nov 2006 01:07:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-5665</strong></p>
  <p>PHP remote file inclusion vulnerability in admin/modules_data.php in the phpBB module Spider Friendly 1.3.10 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-5665">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2006-5610 – PHP remote file inclusion vulnerability in player/includes/common.php in Teake N...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-5610</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-5610</guid>
    <pubDate>Tue, 31 Oct 2006 00:07:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2006-5610</strong></p>
  <p>PHP remote file inclusion vulnerability in player/includes/common.php in Teake Nutma Foing, as modified in Fully Modded phpBB (phpbbfm) 2021.4.40, allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-5610">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-5526 – Multiple PHP remote file inclusion vulnerabilities in Teake Nutma Foing, as modi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-5526</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-5526</guid>
    <pubDate>Thu, 26 Oct 2006 17:07:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-5526</strong></p>
  <p>Multiple PHP remote file inclusion vulnerabilities in Teake Nutma Foing, as modified in Fully Modded phpBB (phpbbfm) 2021.4.40 and earlier, allow remote attackers to execute arbitrary PHP code via a URL in the foing_root_path parameter in (a) faq.php, (b) index.php, (c) list.php, (d) login.php, (e) playlist.php, (f) song.php, (g) gen_m3u.php, (h) view_artist.php, (i) view_song.php, (j) flash/set_…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-5526">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-5435 – PHP remote file inclusion vulnerability in groupcp.php in phpBB 2.0.10 and earli...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-5435</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-5435</guid>
    <pubDate>Fri, 20 Oct 2006 23:07:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-5435</strong></p>
  <p>PHP remote file inclusion vulnerability in groupcp.php in phpBB 2.0.10 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.  NOTE: CVE and the vendor dispute this vulnerability because $phpbb_root_path is defined before use</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-5435">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-5415 – PHP remote file inclusion vulnerability in includes/functions_newshr.php in the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-5415</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-5415</guid>
    <pubDate>Fri, 20 Oct 2006 14:07:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-5415</strong></p>
  <p>PHP remote file inclusion vulnerability in includes/functions_newshr.php in the News Defilante Horizontale 4.1.1 and earlier module for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-5415">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-5385 – PHP remote file inclusion vulnerability in admin/admin_spam.php in the SpamOboro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-5385</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-5385</guid>
    <pubDate>Wed, 18 Oct 2006 19:07:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-5385</strong></p>
  <p>PHP remote file inclusion vulnerability in admin/admin_spam.php in the SpamOborona 1.0b and earlier phpBB module allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-5385">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-5387 – PHP remote file inclusion vulnerability in mods/iai/includes/constants.php in th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-5387</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-5387</guid>
    <pubDate>Wed, 18 Oct 2006 19:07:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-5387</strong></p>
  <p>PHP remote file inclusion vulnerability in mods/iai/includes/constants.php in the PlusXL 20_272 and earlier phpBB module allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-5387">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-5325 – Multiple PHP remote file inclusion vulnerabilities in Dimitri Seitz Security Sui...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-5325</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-5325</guid>
    <pubDate>Tue, 17 Oct 2006 17:07:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-5325</strong></p>
  <p>Multiple PHP remote file inclusion vulnerabilities in Dimitri Seitz Security Suite IP Logger in dwingmods for phpBB allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter in (1) mkb.php, (2) iplogger.php, (3) admin_board2.php, or (4) admin_logger.php in includes/, different vectors than CVE-2006-5224.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-5325">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-5326 – PHP remote file inclusion vulnerability in language/lang/lang_contact_faq.php in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-5326</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-5326</guid>
    <pubDate>Tue, 17 Oct 2006 17:07:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-5326</strong></p>
  <p>PHP remote file inclusion vulnerability in language/lang/lang_contact_faq.php in the Prillian French 0.8.0 and earlier module for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.  NOTE: the provenance of this information is unknown; the details are obtained from third party information.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-5326">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-5309 – PHP remote file inclusion vulnerability in language/lang_french/lang_prillian_fa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-5309</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-5309</guid>
    <pubDate>Tue, 17 Oct 2006 16:07:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-5309</strong></p>
  <p>PHP remote file inclusion vulnerability in language/lang_french/lang_prillian_faq.php in the Prillian French 0.8.0 and earlier module for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-5309">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-5311 – PHP remote file inclusion vulnerability in includes/archive/archive_topic.php in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-5311</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-5311</guid>
    <pubDate>Tue, 17 Oct 2006 16:07:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-5311</strong></p>
  <p>PHP remote file inclusion vulnerability in includes/archive/archive_topic.php in Buzlas 2006-1 Full allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-5311">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-5312 – PHP remote file inclusion vulnerability in shoutbox.php in the Ajax Shoutbox 0.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-5312</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-5312</guid>
    <pubDate>Tue, 17 Oct 2006 16:07:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-5312</strong></p>
  <p>PHP remote file inclusion vulnerability in shoutbox.php in the Ajax Shoutbox 0.0.5 and earlier module for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-5312">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-5235 – PHP remote file inclusion vulnerability in includes/functions_kb.php in Dimensio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-5235</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-5235</guid>
    <pubDate>Wed, 11 Oct 2006 01:07:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-5235</strong></p>
  <p>PHP remote file inclusion vulnerability in includes/functions_kb.php in Dimension of phpBB 0.2.6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-5235">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-5222 – Multiple PHP remote file inclusion vulnerabilities in Dimension of phpBB 0.2.6 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-5222</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-5222</guid>
    <pubDate>Tue, 10 Oct 2006 21:07:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-5222</strong></p>
  <p>Multiple PHP remote file inclusion vulnerabilities in Dimension of phpBB 0.2.6 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter in (1) includes/themen_portal_mitte.php or (2) includes/logger_engine.php.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-5222">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-5223 – PHP remote file inclusion vulnerability in includes/functions_user_viewed_posts...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-5223</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-5223</guid>
    <pubDate>Tue, 10 Oct 2006 21:07:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-5223</strong></p>
  <p>PHP remote file inclusion vulnerability in includes/functions_user_viewed_posts.php in the Nivisec User Viewed Posts Tracker module 1.0 and earlier for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-5223">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-5224 – PHP remote file inclusion vulnerability in includes/logger_engine.php in Dimitri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-5224</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-5224</guid>
    <pubDate>Tue, 10 Oct 2006 21:07:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-5224</strong></p>
  <p>PHP remote file inclusion vulnerability in includes/logger_engine.php in Dimitri Seitz Security Suite IP Logger 1.0.0 in dwingmods for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-5224">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-5187 – PHP remote file inclusion vulnerability in includes/functions.php in Bulletin Bo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-5187</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-5187</guid>
    <pubDate>Tue, 10 Oct 2006 04:06:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-5187</strong></p>
  <p>PHP remote file inclusion vulnerability in includes/functions.php in Bulletin Board Ace (BBaCE) 3.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-5187">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-5209 – PHP remote file inclusion vulnerability in admin/admin_topic_action_logging.php ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-5209</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-5209</guid>
    <pubDate>Tue, 10 Oct 2006 04:06:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-5209</strong></p>
  <p>PHP remote file inclusion vulnerability in admin/admin_topic_action_logging.php in Admin Topic Action Logging Mod 0.95 and earlier, as used in phpBB 2.0 up to 2.0.21, allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-5209">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-5083 – PHP remote file inclusion vulnerability in includes/functions_portal.php in Inte...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-5083</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-5083</guid>
    <pubDate>Fri, 29 Sep 2006 00:07:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-5083</strong></p>
  <p>PHP remote file inclusion vulnerability in includes/functions_portal.php in Integrated MODs (IM) Portal 1.2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-5083">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-4968 – PHP remote file inclusion vulnerability in includes/functions_admin.php in PNphp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-4968</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-4968</guid>
    <pubDate>Mon, 25 Sep 2006 01:07:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-4968</strong></p>
  <p>PHP remote file inclusion vulnerability in includes/functions_admin.php in PNphpBB 1.2g allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-4968">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-4893 – PHP remote file inclusion vulnerability in bb_usage_stats/includes/bb_usage_stat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-4893</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-4893</guid>
    <pubDate>Tue, 19 Sep 2006 22:07:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-4893</strong></p>
  <p>PHP remote file inclusion vulnerability in bb_usage_stats/includes/bb_usage_stats.php in phpBB XS 0.58 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter, a different vector than CVE-2006-4780.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-4893">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-4779 – PHP remote file inclusion vulnerability in includes/functions_portal.php in Vitr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-4779</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-4779</guid>
    <pubDate>Thu, 14 Sep 2006 10:07:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-4779</strong></p>
  <p>PHP remote file inclusion vulnerability in includes/functions_portal.php in Vitrax Premodded phpBB 1.0.6-R3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-4779">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-4780 – PHP remote file inclusion vulnerability in includes/functions.php in phpBB XS 0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-4780</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-4780</guid>
    <pubDate>Thu, 14 Sep 2006 10:07:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-4780</strong></p>
  <p>PHP remote file inclusion vulnerability in includes/functions.php in phpBB XS 0.58 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-4780">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-4365 – Multiple PHP remote file inclusion vulnerabilities in VistaBB 2.0.33 and earlier...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-4365</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-4365</guid>
    <pubDate>Sat, 26 Aug 2006 21:04:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-4365</strong></p>
  <p>Multiple PHP remote file inclusion vulnerabilities in VistaBB 2.0.33 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter in (1) includes/functions_mod_user.php or (2) includes/functions_portal.php.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-4365">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-4367 – SQL injection vulnerability in alltopics.php in the All Topics Hack 1.5.0 and ea...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-4367</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-4367</guid>
    <pubDate>Sat, 26 Aug 2006 21:04:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-4367</strong></p>
  <p>SQL injection vulnerability in alltopics.php in the All Topics Hack 1.5.0 and earlier for phpBB 2.0.21 allows remote attackers to execute arbitrary SQL commands via the start parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-4367">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-4368 – PHP remote file inclusion vulnerability in includes/functions_portal.php in Inte...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-4368</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-4368</guid>
    <pubDate>Sat, 26 Aug 2006 21:04:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-4368</strong></p>
  <p>PHP remote file inclusion vulnerability in includes/functions_portal.php in IntegraMOD Portal 2.x and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-4368">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-4036 – PHP remote file inclusion vulnerability in includes/usercp_register.php in ZoneM...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-4036</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-4036</guid>
    <pubDate>Wed, 09 Aug 2006 22:04:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-4036</strong></p>
  <p>PHP remote file inclusion vulnerability in includes/usercp_register.php in ZoneMetrics ZoneX Publishers Gold Edition 1.0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-4036">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-3940 – Multiple SQL injection vulnerabilities in phpbb-Auction allow remote attackers t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-3940</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-3940</guid>
    <pubDate>Mon, 31 Jul 2006 22:04:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-3940</strong></p>
  <p>Multiple SQL injection vulnerabilities in phpbb-Auction allow remote attackers to execute arbitrary SQL commands via (1) the ar parameter in auction_room.php and (2) the u parameter in auction_store.php. NOTE: the auction_rating.php vector is already covered by CVE-2005-1234.  NOTE: the original disclosure states that the product name is "PHP-Auction", but this is probably an error.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-3940">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-3028 – PHP remote file inclusion vulnerability in stat_modules/users_age/module.php in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-3028</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-3028</guid>
    <pubDate>Thu, 15 Jun 2006 10:02:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-3028</strong></p>
  <p>PHP remote file inclusion vulnerability in stat_modules/users_age/module.php in Minerva 2.0.8a Build 237 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-3028">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-2865 – PHP remote file inclusion vulnerability in template.php in phpBB 2 allows remote...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-2865</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-2865</guid>
    <pubDate>Tue, 06 Jun 2006 20:06:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-2865</strong></p>
  <p>PHP remote file inclusion vulnerability in template.php in phpBB 2 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.  NOTE: followup posts have disputed this issue, stating that template.php does not appear in phpBB and does not use a $page variable.  It is possible that this is a site-specific vulnerability, or an issue in a mod</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-2865">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-2693 – Directory traversal vulnerability in admin/admin_hacks_list.php in Nivisec Hacks...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-2693</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-2693</guid>
    <pubDate>Wed, 31 May 2006 10:06:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-2693</strong></p>
  <p>Directory traversal vulnerability in admin/admin_hacks_list.php in Nivisec Hacks List 1.20 and earlier for phpBB, when register_globals is enabled, allows remote attackers to read arbitrary files via a ".." in the phpEx parameter.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-2693">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-2507 – Multiple PHP remote file inclusion vulnerabilities in Teake Nutma Foing 0.2.0 th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-2507</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-2507</guid>
    <pubDate>Mon, 22 May 2006 19:02:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-2507</strong></p>
  <p>Multiple PHP remote file inclusion vulnerabilities in Teake Nutma Foing 0.2.0 through 0.7.0, as used with phpBB, allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter in (1) index.php, (2) song.php, (3) faq.php, (4) list.php, (5) gen_m3u.php, and (6) playlist.php.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-2507">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-2360 – SQL injection vulnerability in charts.php in the Chart mod for phpBB allows remo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-2360</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-2360</guid>
    <pubDate>Mon, 15 May 2006 16:06:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-2360</strong></p>
  <p>SQL injection vulnerability in charts.php in the Chart mod for phpBB allows remote attackers to execute arbitrary SQL commands via the id parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-2360">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-2361 – PHP remote file inclusion vulnerability in pafiledb_constants.php in Download Ma...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-2361</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-2361</guid>
    <pubDate>Mon, 15 May 2006 16:06:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-2361</strong></p>
  <p>PHP remote file inclusion vulnerability in pafiledb_constants.php in Download Manager (mxBB pafiledb) integration, as used with phpBB, allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-2361">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-2283 – Multiple PHP remote file inclusion vulnerabilities in SpiffyJr phpRaid 2.9.5 thr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-2283</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-2283</guid>
    <pubDate>Wed, 10 May 2006 02:14:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-2283</strong></p>
  <p>Multiple PHP remote file inclusion vulnerabilities in SpiffyJr phpRaid 2.9.5 through 3.0.b3 allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter in (1) auth.php and (2) auth_phpbb when the phpBB portal is enabled, and via a URL in the smf_root_path parameter in (3) auth.php and (4) auth_SMF when the SMF portal is enabled.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-2283">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-2151 – PHP remote file inclusion vulnerability in toplist.php in phpBB TopList 1.3.8 an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-2151</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-2151</guid>
    <pubDate>Wed, 03 May 2006 10:02:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-2151</strong></p>
  <p>PHP remote file inclusion vulnerability in toplist.php in phpBB TopList 1.3.8 and earlier, when register_globals is enabled, allows remote attackers to include arbitrary files via the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-2151">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-2152 – PHP remote file inclusion vulnerability in admin/addentry.php in phpBB Advanced ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-2152</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-2152</guid>
    <pubDate>Wed, 03 May 2006 10:02:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-2152</strong></p>
  <p>PHP remote file inclusion vulnerability in admin/addentry.php in phpBB Advanced Guestbook 2.4.0 and earlier, when register_globals is enabled, allows remote attackers to include arbitrary files via the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-2152">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2005-4528 – SQL injection vulnerability in the Chatspot 2.0.0a7 module for phpBB allows remo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2005-4528</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2005-4528</guid>
    <pubDate>Wed, 28 Dec 2005 01:03:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2005-4528</strong></p>
  <p>SQL injection vulnerability in the Chatspot 2.0.0a7 module for phpBB allows remote attackers to execute arbitrary SQL commands via unknown vectors.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2005-4528">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2005-4529 – The Chatspot 2.0.0a7 module for phpBB might allow remote attackers to impersonat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2005-4529</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2005-4529</guid>
    <pubDate>Wed, 28 Dec 2005 01:03:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2005-4529</strong></p>
  <p>The Chatspot 2.0.0a7 module for phpBB might allow remote attackers to impersonate other users via unknown vectors.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2005-4529">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2005-3536 – SQL injection vulnerability in phpBB 2 before 2.0.18 allows remote attackers to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2005-3536</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2005-3536</guid>
    <pubDate>Thu, 22 Dec 2005 23:03:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2005-3536</strong></p>
  <p>SQL injection vulnerability in phpBB 2 before 2.0.18 allows remote attackers to execute arbitrary SQL commands via the topic type.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2005-3536">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
