<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – phpBB</title>
  <link>https://cvedaily.com/pages/tags/phpbb.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/phpbb.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – phpBB</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:52 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-29199 – phpBB before 3.3.16 is vulnerable to Host Header Injection that can lead to pass...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-29199</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-29199</guid>
    <pubDate>Mon, 04 May 2026 07:15:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-29199</strong></p>
  <p>phpBB before 3.3.16 is vulnerable to Host Header Injection that can lead to password rest link poisoning. When force_server_vars is disabled, the servers hostname may be extracted from the HTTP Host header which is used to generate the password reset link URL. An attacker who can manipulate the Host header (e.g. through misconfigured host setup or missing header validation by the webserver) can c…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-29199">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-70811 – Cross Site Request Forgery vulnerability in Phpbb phbb3 v.3.3.15 allows a local ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-70811</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-70811</guid>
    <pubDate>Thu, 09 Apr 2026 15:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-70811</strong></p>
  <p>Cross Site Request Forgery vulnerability in Phpbb phbb3 v.3.3.15 allows a local attacker to execute arbitrary code via the Admin Control Panel icon management functionality.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-70811">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-70810 – Cross Site Request Forgery vulnerability in Phpbb phbb3 v.3.3.15 allows a local ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-70810</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-70810</guid>
    <pubDate>Thu, 09 Apr 2026 15:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-70810</strong></p>
  <p>Cross Site Request Forgery vulnerability in Phpbb phbb3 v.3.3.15 allows a local attacker to execute arbitrary code via the login function and the authentication mechanism</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-70810">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25685 – phpBB contains an arbitrary file upload vulnerability that allows authenticated ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25685</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25685</guid>
    <pubDate>Sun, 05 Apr 2026 21:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25685</strong></p>
  <p>phpBB contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by exploiting the plupload functionality and phar:// stream wrapper. Attackers can upload a crafted zip file containing serialized PHP objects that execute arbitrary code when deserialized through the imagick parameter in attachment settings.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25685">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-32575 – Cross-Site Request Forgery (CSRF) vulnerability in axew3 WP w3all phpBB wp-w3all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-32575</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-32575</guid>
    <pubDate>Wed, 09 Apr 2025 17:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-32575</strong></p>
  <p>Cross-Site Request Forgery (CSRF) vulnerability in axew3 WP w3all phpBB wp-w3all-phpbb-integration allows Reflected XSS.This issue affects WP w3all phpBB: from n/a through <= 2.9.9.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-32575">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-32274 – Cross-Site Request Forgery (CSRF) vulnerability in axew3 WP w3all phpBB wp-w3all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-32274</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-32274</guid>
    <pubDate>Fri, 04 Apr 2025 16:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-32274</strong></p>
  <p>Cross-Site Request Forgery (CSRF) vulnerability in axew3 WP w3all phpBB wp-w3all-phpbb-integration allows Cross Site Request Forgery.This issue affects WP w3all phpBB: from n/a through <= 2.9.8.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-32274">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2023-5917 – A vulnerability, which was classified as problematic, has been found in phpBB up...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-5917</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-5917</guid>
    <pubDate>Thu, 02 Nov 2023 11:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2023-5917</strong></p>
  <p>A vulnerability, which was classified as problematic, has been found in phpBB up to 3.3.10. This issue affects the function main of the file phpBB/includes/acp/acp_icons.php of the component Smiley Pack Handler. The manipulation of the argument pak leads to cross site scripting. The attack may be initiated remotely. Upgrading to version 3.3.11 is able to address this issue. The patch is named ccf…</p>
  <p><strong>CVSS:</strong> 2.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-5917">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-8226 – A vulnerability exists in phpBB &lt;v3.2.10 and &lt;v3.3.1 which allowed remote image ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-8226</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-8226</guid>
    <pubDate>Mon, 17 Aug 2020 16:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-8226</strong></p>
  <p>A vulnerability exists in phpBB <v3.2.10 and <v3.3.1 which allowed remote image dimensions check to be used to SSRF.</p>
  <p><strong>CVSS:</strong> 5.8 · <strong>CWE:</strong> CWE-610</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-8226">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-16108 – phpBB 3.2.7 allows adding an arbitrary Cascading Style Sheets (CSS) token sequen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-16108</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-16108</guid>
    <pubDate>Fri, 20 Mar 2020 00:17:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-16108</strong></p>
  <p>phpBB 3.2.7 allows adding an arbitrary Cascading Style Sheets (CSS) token sequence to a page through BBCode.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-16108">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-16107 – Missing form token validation in phpBB 3.2.7 allows CSRF in deleting post attach...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-16107</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-16107</guid>
    <pubDate>Wed, 11 Mar 2020 13:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-16107</strong></p>
  <p>Missing form token validation in phpBB 3.2.7 allows CSRF in deleting post attachments.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-16107">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-5502 – phpBB 3.2.8 allows a CSRF attack that can approve pending group memberships.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-5502</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-5502</guid>
    <pubDate>Wed, 15 Jan 2020 00:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-5502</strong></p>
  <p>phpBB 3.2.8 allows a CSRF attack that can approve pending group memberships.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-5502">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-5501 – phpBB 3.2.8 allows a CSRF attack that can modify a group avatar.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-5501</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-5501</guid>
    <pubDate>Wed, 15 Jan 2020 00:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-5501</strong></p>
  <p>phpBB 3.2.8 allows a CSRF attack that can modify a group avatar.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-5501">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2011-0544 – phpbb 3.0.x-3.0.6 has an XSS vulnerability via the [flash] BB tag.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-0544</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-0544</guid>
    <pubDate>Thu, 14 Nov 2019 00:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2011-0544</strong></p>
  <p>phpbb 3.0.x-3.0.6 has an XSS vulnerability via the [flash] BB tag.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-0544">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-16993 – In phpBB before 3.1.7-PL1, includes/acp/acp_bbcodes.php has improper verificatio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-16993</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-16993</guid>
    <pubDate>Mon, 30 Sep 2019 12:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-16993</strong></p>
  <p>In phpBB before 3.1.7-PL1, includes/acp/acp_bbcodes.php has improper verification of a CSRF token on the BBCode page in the Administration Control Panel. An actual CSRF attack is possible if an attacker also manages to retrieve the session id of a reauthenticated administrator prior to targeting them.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-16993">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-13376 – phpBB version 3.2.7 allows the stealing of an Administration Control Panel sessi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-13376</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-13376</guid>
    <pubDate>Fri, 27 Sep 2019 13:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-13376</strong></p>
  <p>phpBB version 3.2.7 allows the stealing of an Administration Control Panel session id by leveraging CSRF in the Remote Avatar feature. The CSRF Token Hijacking leads to stored XSS</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-13376">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-11767 – Server side request forgery (SSRF) in phpBB before 3.2.6 allows checking for the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-11767</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-11767</guid>
    <pubDate>Sun, 05 May 2019 06:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-11767</strong></p>
  <p>Server side request forgery (SSRF) in phpBB before 3.2.6 allows checking for the existence of files and services on the local network of the host through the remote avatar upload function.</p>
  <p><strong>CVSS:</strong> 5.8 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-11767">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-9826 – The fulltext search component in phpBB before 3.2.6 allows Denial of Service.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-9826</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-9826</guid>
    <pubDate>Thu, 02 May 2019 21:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-9826</strong></p>
  <p>The fulltext search component in phpBB before 3.2.6 allows Denial of Service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-9826">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-19274 – Passing an absolute path to a file_exists check in phpBB before 3.2.4 allows Rem...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-19274</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-19274</guid>
    <pubDate>Sat, 17 Nov 2018 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-19274</strong></p>
  <p>Passing an absolute path to a file_exists check in phpBB before 3.2.4 allows Remote Code Execution through Object Injection by employing Phar deserialization when an attacker has access to the Admin Control Panel with founder permissions.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-19274">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-1000419 – phpBB version 3.2.0 is vulnerable to SSRF in the Remote Avatar function resultin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-1000419</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-1000419</guid>
    <pubDate>Tue, 02 Jan 2018 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-1000419</strong></p>
  <p>phpBB version 3.2.0 is vulnerable to SSRF in the Remote Avatar function resulting allowing an attacker to perform port scanning, requesting internal content and potentially attacking such internal services via the web application.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-1000419">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2015-3880 – Open redirect vulnerability in phpBB before 3.0.14 and 3.1.x before 3.1.4 allows...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-3880</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-3880</guid>
    <pubDate>Tue, 19 Sep 2017 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2015-3880</strong></p>
  <p>Open redirect vulnerability in phpBB before 3.0.14 and 3.1.x before 3.1.4 allows remote attackers to redirect users of Google Chrome to arbitrary web sites and conduct phishing attacks via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-3880">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2015-1432 – The message_options function in includes/ucp/ucp_pm_options.php in phpBB before ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-1432</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-1432</guid>
    <pubDate>Tue, 10 Feb 2015 17:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2015-1432</strong></p>
  <p>The message_options function in includes/ucp/ucp_pm_options.php in phpBB before 3.0.13 does not properly validate the form key, which allows remote attackers to conduct CSRF attacks and change the full folder setting via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-1432">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2015-1431 – Cross-site scripting (XSS) vulnerability in includes/startup.php in phpBB before...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-1431</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-1431</guid>
    <pubDate>Tue, 10 Feb 2015 17:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2015-1431</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in includes/startup.php in phpBB before 3.0.13 allows remote attackers to inject arbitrary web script or HTML via vectors related to "Relative Path Overwrite."</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-1431">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2010-1630 – Unspecified vulnerability in posting.php in phpBB before 3.0.5 has unknown impac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1630</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1630</guid>
    <pubDate>Wed, 19 May 2010 22:30:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2010-1630</strong></p>
  <p>Unspecified vulnerability in posting.php in phpBB before 3.0.5 has unknown impact and attack vectors related to the use of a "forum id" in circumstances related to a "global announcement."</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1630">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2010-1627 – feed.php in phpBB 3.0.7 before 3.0.7-PL1 does not properly check permissions for...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1627</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1627</guid>
    <pubDate>Wed, 19 May 2010 22:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2010-1627</strong></p>
  <p>feed.php in phpBB 3.0.7 before 3.0.7-PL1 does not properly check permissions for feeds, which allows remote attackers to bypass intended access restrictions via unspecified attack vectors related to permission settings on a private forum.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1627">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2009-3052 – SQL injection vulnerability in root/includes/prime_quick_style.php in the Prime ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-3052</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-3052</guid>
    <pubDate>Thu, 03 Sep 2009 17:30:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2009-3052</strong></p>
  <p>SQL injection vulnerability in root/includes/prime_quick_style.php in the Prime Quick Style addon before 1.2.3 for phpBB 3 allows remote authenticated users to execute arbitrary SQL commands via the prime_quick_style parameter to ucp.php.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-3052">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2008-7143 – phpBB 2.0.23 includes the session ID in a request to modcp.php when the moderato...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-7143</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-7143</guid>
    <pubDate>Tue, 01 Sep 2009 16:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2008-7143</strong></p>
  <p>phpBB 2.0.23 includes the session ID in a request to modcp.php when the moderator or administrator closes a thread, which allows remote attackers to hijack the session via a post in the thread containing a URL to a remotely hosted image, which might include the session ID in the Referer header.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-7143">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2008-6507 – Unspecified vulnerability in phpBB before 3.0.4 allows attackers to obtain sensi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-6507</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-6507</guid>
    <pubDate>Mon, 23 Mar 2009 16:30:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2008-6507</strong></p>
  <p>Unspecified vulnerability in phpBB before 3.0.4 allows attackers to obtain sensitive information via unknown vectors related to the lack of password prompts for a private message that quotes a post in a password-protected forum.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-6507">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2008-6506 – Unspecified vulnerability in phpBB before 3.0.4 allows attackers to bypass inten...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-6506</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-6506</guid>
    <pubDate>Mon, 23 Mar 2009 16:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2008-6506</strong></p>
  <p>Unspecified vulnerability in phpBB before 3.0.4 allows attackers to bypass intended access restrictions and activate de-activated accounts via unknown vectors.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-6506">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-6377 – PHP remote file inclusion vulnerability in include/global.php in Multi SEO phpBB...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-6377</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-6377</guid>
    <pubDate>Mon, 02 Mar 2009 19:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-6377</strong></p>
  <p>PHP remote file inclusion vulnerability in include/global.php in Multi SEO phpBB 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the pfad parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-6377">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-6314 – SQL injection vulnerability in tag_board.php in the Tag Board module 4.0 and ear...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-6314</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-6314</guid>
    <pubDate>Fri, 27 Feb 2009 11:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-6314</strong></p>
  <p>SQL injection vulnerability in tag_board.php in the Tag Board module 4.0 and earlier for phpBB allows remote attackers to execute arbitrary SQL commands via the id parameter in a delete action.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-6314">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-6301 – SQL injection vulnerability in shoutbox_view.php in the Small ShoutBox module 1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-6301</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-6301</guid>
    <pubDate>Thu, 26 Feb 2009 16:17:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-6301</strong></p>
  <p>SQL injection vulnerability in shoutbox_view.php in the Small ShoutBox module 1.4 for phpBB allows remote attackers to execute arbitrary SQL commands via the id parameter in a delete action.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-6301">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-5585 – Multiple PHP remote file inclusion vulnerabilities in lcxBBportal 0.1 Alpha 2 al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-5585</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-5585</guid>
    <pubDate>Tue, 16 Dec 2008 19:07:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-5585</strong></p>
  <p>Multiple PHP remote file inclusion vulnerabilities in lcxBBportal 0.1 Alpha 2 allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter to (1) portal/includes/portal_block.php and (2) includes/acp/acp_lcxbbportal.php.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-5585">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2008-4125 – The search function in phpBB 2.x provides a search_id value that leaks the state...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-4125</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-4125</guid>
    <pubDate>Thu, 18 Sep 2008 17:59:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2008-4125</strong></p>
  <p>The search function in phpBB 2.x provides a search_id value that leaks the state of PHP's PRNG, which allows remote attackers to obtain potentially sensitive information, as demonstrated by a cross-application attack against WordPress, a different vulnerability than CVE-2006-0632.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-4125">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2008-3315 – Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.8.10 allow re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-3315</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-3315</guid>
    <pubDate>Fri, 25 Jul 2008 16:41:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2008-3315</strong></p>
  <p>Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.8.10 allow remote attackers to inject arbitrary web script or HTML via the (1) query string to (a) announcements/messages.php; (b) lostPassword.php and (c) profile.php in auth/; (d) calendar/myagenda.php; (e) group/group.php; (f) learningPath.php, (g) learningPathList.php, and (h) module.php in learnPath/; (i) phpbb/index.php; (j)…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-3315">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2008-3260 – Multiple cross-site scripting (XSS) vulnerabilities in Claroline before 1.8.10 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-3260</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-3260</guid>
    <pubDate>Tue, 22 Jul 2008 17:41:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2008-3260</strong></p>
  <p>Multiple cross-site scripting (XSS) vulnerabilities in Claroline before 1.8.10 allow remote attackers to inject arbitrary web script or HTML via (1) the cwd parameter in a rqMkHtml action to document/rqmkhtml.php, or the query string to (2) announcements/announcements.php, (3) calendar/agenda.php, (4) course/index.php, (5) course_description/index.php, (6) document/document.php, (7) exercise/exer…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-3260">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2008-3224 – Unspecified vulnerability in phpBB before 3.0.1 has unknown impact and attack ve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-3224</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-3224</guid>
    <pubDate>Fri, 18 Jul 2008 16:41:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2008-3224</strong></p>
  <p>Unspecified vulnerability in phpBB before 3.0.1 has unknown impact and attack vectors related to "urls gone through redirect() being used within login_box()."</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-3224">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2008-2481 – PHP remote file inclusion vulnerability in authentication/phpbb3/phpbb3.function...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-2481</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-2481</guid>
    <pubDate>Wed, 28 May 2008 15:32:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2008-2481</strong></p>
  <p>PHP remote file inclusion vulnerability in authentication/phpbb3/phpbb3.functions.php in phpRaider 1.0.7 and 1.0.7a, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the pConfig_auth[phpbb_path] parameter.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-2481">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2008-1766 – Multiple unspecified vulnerabilities in phpBB before 3.0.1 have unknown impact a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-1766</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-1766</guid>
    <pubDate>Sat, 12 Apr 2008 20:05:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2008-1766</strong></p>
  <p>Multiple unspecified vulnerabilities in phpBB before 3.0.1 have unknown impact and attack vectors, related to "two minor security-related bugs."</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-1766">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-1565 – Directory traversal vulnerability in forum/irc/irc.php in the PJIRC 0.5 module f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-1565</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-1565</guid>
    <pubDate>Mon, 31 Mar 2008 22:44:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-1565</strong></p>
  <p>Directory traversal vulnerability in forum/irc/irc.php in the PJIRC 0.5 module for phpBB allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the phpEx parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-1565">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-1512 – Directory traversal vulnerability in admin/admin_xs.php in eXtreme Styles module...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-1512</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-1512</guid>
    <pubDate>Tue, 25 Mar 2008 23:44:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-1512</strong></p>
  <p>Directory traversal vulnerability in admin/admin_xs.php in eXtreme Styles module (XS-Mod) 2.3.1 and 2.4.0 for phpBB allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the phpEx parameter. NOTE: some of these details are obtained from third party information.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-1512">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-1350 – SQL injection vulnerability in kb.php in Fully Modded phpBB (phpbbfm) 80220 allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-1350</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-1350</guid>
    <pubDate>Mon, 17 Mar 2008 16:44:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-1350</strong></p>
  <p>SQL injection vulnerability in kb.php in Fully Modded phpBB (phpbbfm) 80220 allows remote attackers to execute arbitrary SQL commands via the k parameter in an article action.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-1350">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-1305 – SQL injection vulnerability in filebase.php in the Filebase mod for phpBB allows...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-1305</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-1305</guid>
    <pubDate>Wed, 12 Mar 2008 17:44:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-1305</strong></p>
  <p>SQL injection vulnerability in filebase.php in the Filebase mod for phpBB allows remote attackers to execute arbitrary SQL commands via the id parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-1305">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2008-1171 – Multiple PHP remote file inclusion vulnerabilities in the 123 Flash Chat Module ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-1171</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-1171</guid>
    <pubDate>Wed, 05 Mar 2008 23:44:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2008-1171</strong></p>
  <p>Multiple PHP remote file inclusion vulnerabilities in the 123 Flash Chat Module for phpBB allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter to (1) 123flashchat.php and (2) phpbb_login_chat.php.  NOTE: CVE disputes this issue because $phpbb_root_path is explicitly set to "./" in both programs</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-1171">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2008-0471 – Cross-site request forgery (CSRF) vulnerability in privmsg.php in phpBB 2.0.22 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-0471</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-0471</guid>
    <pubDate>Tue, 29 Jan 2008 20:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2008-0471</strong></p>
  <p>Cross-site request forgery (CSRF) vulnerability in privmsg.php in phpBB 2.0.22 allows remote attackers to delete private messages (PM) as arbitrary users via a deleteall action.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-0471">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-6223 – SQL injection vulnerability in garage.php in phpBB Garage 1.2.0 Beta3 allows rem...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-6223</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-6223</guid>
    <pubDate>Tue, 04 Dec 2007 17:46:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-6223</strong></p>
  <p>SQL injection vulnerability in garage.php in phpBB Garage 1.2.0 Beta3 allows remote attackers to execute arbitrary SQL commands via the make_id parameter in a search action in browse mode.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-6223">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2007-6088 – PHP remote file inclusion vulnerability in includes/functions_mod_user.php in ph...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-6088</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-6088</guid>
    <pubDate>Thu, 22 Nov 2007 00:46:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2007-6088</strong></p>
  <p>PHP remote file inclusion vulnerability in includes/functions_mod_user.php in phpBBViet 02.03.07 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-6088">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-5688 – Multiple SQL injection vulnerabilities in directory.php in the Multi-Forums (aka...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-5688</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-5688</guid>
    <pubDate>Mon, 29 Oct 2007 19:46:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-5688</strong></p>
  <p>Multiple SQL injection vulnerabilities in directory.php in the Multi-Forums (aka Multi Host Forum Pro) module 1.3.3, for phpBB and Invision Power Board (IPB or IP.Board), allow remote attackers to execute arbitrary SQL commands via the (1) go and (2) cat parameters.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-5688">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2007-5173 – PHP remote file inclusion vulnerability in includes/openid/Auth/OpenID/BBStore.p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-5173</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-5173</guid>
    <pubDate>Wed, 03 Oct 2007 14:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2007-5173</strong></p>
  <p>PHP remote file inclusion vulnerability in includes/openid/Auth/OpenID/BBStore.php in phpBB Openid 0.2.0 allows remote attackers to execute arbitrary PHP code via a URL in the openid_root_path parameter.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-5173">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2007-5178 – contrib/mx_glance_sdesc.php in the mx_glance 2.3.3 module for mxBB places a crit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-5178</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-5178</guid>
    <pubDate>Wed, 03 Oct 2007 14:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2007-5178</strong></p>
  <p>contrib/mx_glance_sdesc.php in the mx_glance 2.3.3 module for mxBB places a critical security check within a comment because of a missing comment delimiter, which allows remote attackers to conduct remote file inclusion attacks and execute arbitrary PHP code via a URL in the mx_root_path parameter.  NOTE: some sources incorrectly state that phpbb_root_path is the affected parameter.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-5178">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2007-5164 – PHP remote file inclusion vulnerability in htmls/forum/includes/topic_review.php...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-5164</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-5164</guid>
    <pubDate>Mon, 01 Oct 2007 05:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2007-5164</strong></p>
  <p>PHP remote file inclusion vulnerability in htmls/forum/includes/topic_review.php in UniversiBO 1.3.4 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.  NOTE: this issue is disputed by CVE because the applicable include is in a function that is not called on a direct request</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-5164">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2007-5140 – PHP remote file inclusion vulnerability in includes/archive/archive_topic.php in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-5140</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-5140</guid>
    <pubDate>Fri, 28 Sep 2007 21:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2007-5140</strong></p>
  <p>PHP remote file inclusion vulnerability in includes/archive/archive_topic.php in IntegraMOD Nederland 1.4.2 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-5140">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2007-5100 – Multiple PHP remote file inclusion vulnerabilities in phpBB Plus 1.53, and 1.53a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-5100</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-5100</guid>
    <pubDate>Wed, 26 Sep 2007 22:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2007-5100</strong></p>
  <p>Multiple PHP remote file inclusion vulnerabilities in phpBB Plus 1.53, and 1.53a before 20070922, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter to (1) language/lang_german/lang_admin_album.php, (2) language/lang_english/lang_main_album.php, and (3) language/lang_english/lang_admin_album.php, different vectors than…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-5100">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2007-5033 – Cross-site scripting (XSS) vulnerability in profile.php in phpBB XS 2 allows rem...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-5033</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-5033</guid>
    <pubDate>Fri, 21 Sep 2007 19:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2007-5033</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in profile.php in phpBB XS 2 allows remote attackers to inject arbitrary web script or HTML via the selfdes parameter in a profile_info editprofile action.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-5033">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2007-5009 – PHP remote file inclusion vulnerability in language/lang_german/lang_main_album...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-5009</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-5009</guid>
    <pubDate>Thu, 20 Sep 2007 21:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2007-5009</strong></p>
  <p>PHP remote file inclusion vulnerability in language/lang_german/lang_main_album.php in phpBB Plus 1.53, and 1.53a before 20070922, allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-5009">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-4984 – SQL injection vulnerability in index.php in the Ktauber.com StylesDemo mod for p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-4984</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-4984</guid>
    <pubDate>Wed, 19 Sep 2007 19:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-4984</strong></p>
  <p>SQL injection vulnerability in index.php in the Ktauber.com StylesDemo mod for phpBB 2.0.xx allows remote attackers to execute arbitrary SQL commands via the s parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-4984">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-4653 – SQL injection vulnerability in links.php in the Links MOD 1.2.2 and earlier for ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-4653</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-4653</guid>
    <pubDate>Tue, 04 Sep 2007 22:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-4653</strong></p>
  <p>SQL injection vulnerability in links.php in the Links MOD 1.2.2 and earlier for phpBB 2.0.22 and earlier allows remote attackers to execute arbitrary SQL commands via the start parameter in a search action.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-4653">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2007-3935 – PHP remote file inclusion vulnerability in link_main.php in the SupaNav 1.0.0 mo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-3935</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-3935</guid>
    <pubDate>Sat, 21 Jul 2007 00:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2007-3935</strong></p>
  <p>PHP remote file inclusion vulnerability in link_main.php in the SupaNav 1.0.0 module for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-3935">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-3697 – PHP remote file inclusion vulnerability in phpbb/sendmsg.php in FlashBB 1.1.8 an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-3697</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-3697</guid>
    <pubDate>Wed, 11 Jul 2007 22:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-3697</strong></p>
  <p>PHP remote file inclusion vulnerability in phpbb/sendmsg.php in FlashBB 1.1.8 and earlier allows remote attackers to execute arbitrary code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-3697">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2006-7208 – PHP remote file inclusion vulnerability in download.php in the Adam van Dongen F...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-7208</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-7208</guid>
    <pubDate>Tue, 26 Jun 2007 23:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2006-7208</strong></p>
  <p>PHP remote file inclusion vulnerability in download.php in the Adam van Dongen Forum (com_forum) component (aka phpBB component) 1.2.4RC3 and earlier for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-7208">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2007-2858 – SQL injection vulnerability in the IP-Search functionality in the IP-Tracking Mo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-2858</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-2858</guid>
    <pubDate>Thu, 24 May 2007 19:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2007-2858</strong></p>
  <p>SQL injection vulnerability in the IP-Search functionality in the IP-Tracking Mod for phpBB 2.0.x allows remote authenticated administrators to execute arbitrary SQL commands via the Search Query field.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-2858">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-2257 – PHP remote file inclusion vulnerability in subscp.php in Fully Modded phpBB2 all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-2257</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-2257</guid>
    <pubDate>Wed, 25 Apr 2007 17:19:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-2257</strong></p>
  <p>PHP remote file inclusion vulnerability in subscp.php in Fully Modded phpBB2 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-2257">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-2208 – Multiple PHP remote file inclusion vulnerabilities in Extreme PHPBB2 3.0 Pre Fin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-2208</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-2208</guid>
    <pubDate>Tue, 24 Apr 2007 20:19:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-2208</strong></p>
  <p>Multiple PHP remote file inclusion vulnerabilities in Extreme PHPBB2 3.0 Pre Final allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter to (1) functions.php or (2) functions_portal.php in includes/.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-2208">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2007-2189 – PHP remote file inclusion vulnerability in admin/admin_album_otf.php in the MX S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-2189</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-2189</guid>
    <pubDate>Tue, 24 Apr 2007 17:19:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2007-2189</strong></p>
  <p>PHP remote file inclusion vulnerability in admin/admin_album_otf.php in the MX Smartor Full Album Pack (FAP) 2.0 RC1 module for mxBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-2189">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-1961 – PHP remote file inclusion vulnerability in mutant_functions.php in the Mutant 0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-1961</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-1961</guid>
    <pubDate>Wed, 11 Apr 2007 10:19:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-1961</strong></p>
  <p>PHP remote file inclusion vulnerability in mutant_functions.php in the Mutant 0.9.2 portal for phpBB 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-1961">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-1839 – Multiple PHP remote file inclusion vulnerabilities in CodeBB 1.1b3 and earlier a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-1839</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-1839</guid>
    <pubDate>Tue, 03 Apr 2007 00:19:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-1839</strong></p>
  <p>Multiple PHP remote file inclusion vulnerabilities in CodeBB 1.1b3 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter to (1) pass_code.php or (2) lang_select.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-1839">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-1818 – PHP remote file inclusion vulnerability in MOD_forum_fields_parse.php in the For...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-1818</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-1818</guid>
    <pubDate>Mon, 02 Apr 2007 23:19:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-1818</strong></p>
  <p>PHP remote file inclusion vulnerability in MOD_forum_fields_parse.php in the Forum picture and META tags 1.7 module for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-1818">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2007-1778 – PHP remote file inclusion vulnerability in db/mysql.php in the Eve-Nuke 0.1 (EN-...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-1778</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-1778</guid>
    <pubDate>Fri, 30 Mar 2007 01:19:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2007-1778</strong></p>
  <p>PHP remote file inclusion vulnerability in db/mysql.php in the Eve-Nuke 0.1 (EN-Forums) module for PHP-Nuke allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-1778">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2007-1695 – PHP remote file inclusion vulnerability in includes/usercp_register.php in phpBB...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-1695</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-1695</guid>
    <pubDate>Tue, 27 Mar 2007 01:19:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2007-1695</strong></p>
  <p>PHP remote file inclusion vulnerability in includes/usercp_register.php in phpBB 2.0.19 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.  NOTE: this issue has been disputed by third-party researchers, stating that the file checks for a global constant and cannot be accessed directly</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-1695">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2006-7174 – PHP remote file inclusion vulnerability in includes/functions.php in the Dimensi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-7174</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-7174</guid>
    <pubDate>Wed, 21 Mar 2007 21:19:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2006-7174</strong></p>
  <p>PHP remote file inclusion vulnerability in includes/functions.php in the Dimension module of phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.  NOTE: this may be the same issue as CVE-2006-5235.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-7174">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-1555 – SQL injection vulnerability in forum.php in the Minerva mod 2.0.21 build 238a an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-1555</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-1555</guid>
    <pubDate>Tue, 20 Mar 2007 22:19:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-1555</strong></p>
  <p>SQL injection vulnerability in forum.php in the Minerva mod 2.0.21 build 238a and earlier for phpBB allows remote attackers to execute arbitrary SQL commands via the c parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-1555">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-7168 – PHP remote file inclusion vulnerability in includes/not_mem.php in the Add Name ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-7168</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-7168</guid>
    <pubDate>Tue, 20 Mar 2007 10:19:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-7168</strong></p>
  <p>PHP remote file inclusion vulnerability in includes/not_mem.php in the Add Name module for PHP allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-7168">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2007-1421 – Multiple PHP remote file inclusion vulnerabilities in Premod SubDog 2 allow remo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-1421</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-1421</guid>
    <pubDate>Tue, 13 Mar 2007 01:19:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2007-1421</strong></p>
  <p>Multiple PHP remote file inclusion vulnerabilities in Premod SubDog 2 allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter to (1) functions_kb.php, (2) themen_portal_mitte.php, or (3) logger_engine.php in includes/.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-1421">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2006-7147 – PHP remote file inclusion vulnerability in includes/functions_mod_user.php in ph...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-7147</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-7147</guid>
    <pubDate>Wed, 07 Mar 2007 20:19:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2006-7147</strong></p>
  <p>PHP remote file inclusion vulnerability in includes/functions_mod_user.php in phpBB Import Tools Mod 0.1.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-7147">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2006-7148 – PHP remote file inclusion vulnerability in includes/bb_usage_stats.php in maluin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-7148</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-7148</guid>
    <pubDate>Wed, 07 Mar 2007 20:19:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2006-7148</strong></p>
  <p>PHP remote file inclusion vulnerability in includes/bb_usage_stats.php in maluinfo 206.2.38 for Brazilian PHPBB allows remote attackers to execute arbitrary PHP code via the phpbb_root_path parameter.  NOTE: this might be the same issues as CVE-2006-4893.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-7148">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2006-7100 – PHP remote file inclusion vulnerability in includes/functions_mod_user.php in ph...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-7100</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-7100</guid>
    <pubDate>Sat, 03 Mar 2007 21:19:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2006-7100</strong></p>
  <p>PHP remote file inclusion vulnerability in includes/functions_mod_user.php in phpBB Insert User 0.1.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-7100">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2006-7076 – Cross-site scripting (XSS) vulnerability in guestbook.php in Advanced Guestbook ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-7076</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-7076</guid>
    <pubDate>Fri, 02 Mar 2007 21:18:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2006-7076</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in guestbook.php in Advanced Guestbook 2.4 for phpBB allows remote attackers to inject arbitrary web script or HTML via the entry parameter.  NOTE: this issue might be resultant from SQL injection.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-7076">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2006-7077 – SQL injection vulnerability in guestbook.php in Advanced Guestbook 2.4 for phpBB...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-7077</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-7077</guid>
    <pubDate>Fri, 02 Mar 2007 21:18:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2006-7077</strong></p>
  <p>SQL injection vulnerability in guestbook.php in Advanced Guestbook 2.4 for phpBB allows remote attackers to execute arbitrary SQl commands via the entry parameter.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-7077">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2006-7090 – PHP remote file inclusion vulnerability in phpbb_security.php in phpBB Security ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-7090</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-7090</guid>
    <pubDate>Fri, 02 Mar 2007 21:18:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2006-7090</strong></p>
  <p>PHP remote file inclusion vulnerability in phpbb_security.php in phpBB Security 1.0.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the php_root_path parameter.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-7090">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2007-1105 – PHP remote file inclusion vulnerability in functions.php in Extreme phpBB (aka p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-1105</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-1105</guid>
    <pubDate>Mon, 26 Feb 2007 17:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2007-1105</strong></p>
  <p>PHP remote file inclusion vulnerability in functions.php in Extreme phpBB (aka phpBB Extreme) 3.0.1 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-1105">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2007-1106 – PHP remote file inclusion vulnerability in includes/functions_nomoketos_rules.ph...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-1106</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-1106</guid>
    <pubDate>Mon, 26 Feb 2007 17:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2007-1106</strong></p>
  <p>PHP remote file inclusion vulnerability in includes/functions_nomoketos_rules.php in the NoMoKeTos Rules 0.0.1 module for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-1106">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2006-7032 – PHP remote file inclusion vulnerability in phpbb/getmsg.php in FlashBB 1.1.5 and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-7032</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-7032</guid>
    <pubDate>Fri, 23 Feb 2007 03:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2006-7032</strong></p>
  <p>PHP remote file inclusion vulnerability in phpbb/getmsg.php in FlashBB 1.1.5 and earlier allows remote attackers to execute arbitrary code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-7032">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-1048 – PHP remote file inclusion vulnerability in admin_rebuild_search.php in phpbb_wor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-1048</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-1048</guid>
    <pubDate>Wed, 21 Feb 2007 17:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-1048</strong></p>
  <p>PHP remote file inclusion vulnerability in admin_rebuild_search.php in phpbb_wordsearch allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-1048">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2006-2219 – phpBB 2.0.20 does not verify user-specified input variable types before being pa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-2219</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-2219</guid>
    <pubDate>Thu, 08 Feb 2007 17:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2006-2219</strong></p>
  <p>phpBB 2.0.20 does not verify user-specified input variable types before being passed to type-dependent functions, which allows remote attackers to obtain sensitive information, as demonstrated by the (1) mode parameter to memberlist.php and the (2) highlight parameter to viewtopic.php that are used as an argument to the htmlspecialchars or urlencode functions, which displays the installation path…</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-2219">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2006-2220 – phpBB 2.0.20 does not properly verify user-specified input variables used as lim...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-2220</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-2220</guid>
    <pubDate>Thu, 08 Feb 2007 17:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2006-2220</strong></p>
  <p>phpBB 2.0.20 does not properly verify user-specified input variables used as limits to SQL queries, which allows remote attackers to obtain sensitive information via a negative LIMIT specification, as demonstrated by the start parameter to memberlist.php, which reveals the SQL query in the resulting error message.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-2220">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-0809 – PHP remote file inclusion vulnerability in includes/class_template.php in Catego...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-0809</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-0809</guid>
    <pubDate>Wed, 07 Feb 2007 11:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-0809</strong></p>
  <p>PHP remote file inclusion vulnerability in includes/class_template.php in Categories hierarchy (aka CH or mod-CH) 2.1.2 in ptirhiikmods allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-0809">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-0761 – PHP remote file inclusion vulnerability in config.php in phpBB ezBoard converter...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-0761</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-0761</guid>
    <pubDate>Tue, 06 Feb 2007 02:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-0761</strong></p>
  <p>PHP remote file inclusion vulnerability in config.php in phpBB ezBoard converter (ezconvert) 0.2 allows remote attackers to execute arbitrary PHP code via a URL in the ezconvert_dir parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-0761">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-0762 – PHP remote file inclusion vulnerability in includes/functions.php in phpBB++ Bui...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-0762</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-0762</guid>
    <pubDate>Tue, 06 Feb 2007 02:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-0762</strong></p>
  <p>PHP remote file inclusion vulnerability in includes/functions.php in phpBB++ Build 100 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-0762">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-0680 – PHP remote file inclusion vulnerability in includes/functions.php in Phpbb Tweak...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-0680</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-0680</guid>
    <pubDate>Sat, 03 Feb 2007 01:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-0680</strong></p>
  <p>PHP remote file inclusion vulnerability in includes/functions.php in Phpbb Tweaked 3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-0680">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-0683 – PHP remote file inclusion vulnerability in includes/functions.php in Omegaboard ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-0683</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-0683</guid>
    <pubDate>Sat, 03 Feb 2007 01:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-0683</strong></p>
  <p>PHP remote file inclusion vulnerability in includes/functions.php in Omegaboard 1.0beta4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-0683">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-0684 – PHP remote file inclusion vulnerability in portal.php in Cerulean Portal System ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-0684</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-0684</guid>
    <pubDate>Sat, 03 Feb 2007 01:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-0684</strong></p>
  <p>PHP remote file inclusion vulnerability in portal.php in Cerulean Portal System 0.7b allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-0684">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-0656 – PHP remote file inclusion vulnerability in includes/functions.php in phpBB2-MODi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-0656</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-0656</guid>
    <pubDate>Thu, 01 Feb 2007 22:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-0656</strong></p>
  <p>PHP remote file inclusion vulnerability in includes/functions.php in phpBB2-MODificat 0.2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-0656">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-0662 – PHP remote file inclusion vulnerability in includes/usercp_viewprofile.php in Ha...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-0662</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-0662</guid>
    <pubDate>Thu, 01 Feb 2007 22:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-0662</strong></p>
  <p>PHP remote file inclusion vulnerability in includes/usercp_viewprofile.php in Hailboards 1.2.0 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-0662">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-0591 – PHP remote file inclusion vulnerability in configure.php in Vu Le An Virtual Pat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-0591</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-0591</guid>
    <pubDate>Tue, 30 Jan 2007 18:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-0591</strong></p>
  <p>PHP remote file inclusion vulnerability in configure.php in Vu Le An Virtual Path (VirtualPath) 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-0591">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-0572 – PHP remote file inclusion vulnerability in include/irc/phpIRC.php in Drunken:Gol...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-0572</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-0572</guid>
    <pubDate>Tue, 30 Jan 2007 17:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-0572</strong></p>
  <p>PHP remote file inclusion vulnerability in include/irc/phpIRC.php in Drunken:Golem Gaming Portal 0.5.1 Alpha 2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-0572">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-0581 – PHP remote file inclusion vulnerability in functions.php in EclipseBB 0.5.0 Lite...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-0581</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-0581</guid>
    <pubDate>Tue, 30 Jan 2007 17:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-0581</strong></p>
  <p>PHP remote file inclusion vulnerability in functions.php in EclipseBB 0.5.0 Lite allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-0581">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-0561 – Multiple PHP remote file inclusion vulnerabilities in Xero Portal 1.2 allow remo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-0561</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-0561</guid>
    <pubDate>Tue, 30 Jan 2007 16:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-0561</strong></p>
  <p>Multiple PHP remote file inclusion vulnerabilities in Xero Portal 1.2 allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter to (1) admin_linkdb.php, (2) admin_forum_prune.php, (3) admin_extensions.php, (4) admin_board.php, (5) admin_attachments.php, or (6) admin_users.php in admin/.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-0561">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2006-6839 – Unspecified vulnerability in phpBB before 2.0.22 has unknown impact and remote a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-6839</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-6839</guid>
    <pubDate>Sun, 31 Dec 2006 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2006-6839</strong></p>
  <p>Unspecified vulnerability in phpBB before 2.0.22 has unknown impact and remote attack vectors related to "criteria for 'bad' redirection targets."</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-6839">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2006-6840 – Unspecified vulnerability in phpBB before 2.0.22 has unknown impact and remote a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-6840</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-6840</guid>
    <pubDate>Sun, 31 Dec 2006 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2006-6840</strong></p>
  <p>Unspecified vulnerability in phpBB before 2.0.22 has unknown impact and remote attack vectors related to a "negative start parameter."</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-6840">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2006-6841 – Certain forms in phpBB before 2.0.22 lack session checks, which has unknown impa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-6841</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-6841</guid>
    <pubDate>Sun, 31 Dec 2006 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2006-6841</strong></p>
  <p>Certain forms in phpBB before 2.0.22 lack session checks, which has unknown impact and remote attack vectors.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-6841">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-6789 – PHP remote file inclusion vulnerability in includes/archive/archive_topic.php in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-6789</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-6789</guid>
    <pubDate>Thu, 28 Dec 2006 00:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-6789</strong></p>
  <p>PHP remote file inclusion vulnerability in includes/archive/archive_topic.php in Phpbbxtra 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-6789">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
