← Back

Jaxultrabb

jaxultrabb

2 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Jaxultrabb
jaxultrabb

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jaxultrabb
1Jaxultrabb
Apr 23, 2026
Jul 2, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Directory traversal vulnerability in viewprofile.php in JaxUltraBB 2.0 and earlier allows remote attackers to read arbitrary local files via a .. (dot dot) in the user parameter. party information.
1Jaxultrabb
1Jaxultrabb
Apr 23, 2026
Oct 25, 2006
N/A· v4
N/A· v3
2.6 LOW· v2
Direct static code injection vulnerability in delete.php in JaxUltraBB (JUBB) 2.0, when register_globals is enabled, allows remote attackers to inject arbitrary web script, HTML, or PHP via the contents parameter, whose...Show more
Direct static code injection vulnerability in delete.php in JaxUltraBB (JUBB) 2.0, when register_globals is enabled, allows remote attackers to inject arbitrary web script, HTML, or PHP via the contents parameter, whose value is prepended to the file specified by the forum parameter.Show less