← Back

Vubb

vubb

7 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Vubb
vubb

CVEs (7)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Vubb
1Vubb
Apr 23, 2026
Dec 2, 2006
N/A· v4
N/A· v3
5.0 MEDIUM· v2
vuBB 0.2.1 and earlier allows remote attackers to obtain sensitive information via a direct request to includes/vubb.php, which leaks the path in an error message.
1Vubb
1Vubb
Apr 23, 2026
Dec 2, 2006
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in vuBB 0.2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter in a register action to index.php, a different vulnerability than CVE-2006-0962.
1Vubb
1Vubb
Apr 16, 2026
Mar 2, 2006
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in vuBB 0.2 allows remote attackers to execute arbitrary SQL commands via the pass parameter in a cookie.
1Vubb
1Vubb
Apr 16, 2026
Dec 31, 2005
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in VUBB alpha rc1 allows remote attackers to inject arbitrary web script or HTML via unspecified fields in the user edit profile.
1Vubb
1Vubb
Apr 16, 2026
Dec 31, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in VUBB alpha rc1 allow remote attackers to execute arbitrary SQL commands via the (1) f parameter to viewforum.php, (2) t parameter to viewtopic.php, and (3) view parameter to user...Show more
Multiple SQL injection vulnerabilities in VUBB alpha rc1 allow remote attackers to execute arbitrary SQL commands via the (1) f parameter to viewforum.php, (2) t parameter to viewtopic.php, and (3) view parameter to usercp.php.Show less
1Vubb
1Vubb
Apr 16, 2026
Nov 6, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
index.php in VUBB alpha rc1 allows remote attackers to obtain the installation path of the application via a viewforum action with the f parameter set to a single quote (').
1Vubb
1Vubb
Apr 16, 2026
Nov 6, 2005
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in index.php in VUBB alpha rc1 allows remote attackers to inject arbitrary web script or HTML via the t parameter in a newreply action.