This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Woltlab First view 2002-10-04
Product Burning Board Last view 2009-09-09
Version Type Application
Update  
Edition  
Language  
Sofware Edition  
Target Software  
Target Hardware  
Other  

Activity : Overall

COMMON PLATFORM ENUMERATION: Repartition per Version

CPE Name Affected CVE
cpe:2.3:a:woltlab:burning_board:2.2.2:*:*:*:*:*:*:* 11
cpe:2.3:a:woltlab:burning_board:2.3.1:*:*:*:*:*:*:* 11
cpe:2.3:a:woltlab:burning_board:2.0_beta_5:*:*:*:*:*:*:* 9
cpe:2.3:a:woltlab:burning_board:2.0_beta_3:*:*:*:*:*:*:* 9
cpe:2.3:a:woltlab:burning_board:2.0_beta_4:*:*:*:*:*:*:* 9
cpe:2.3:a:woltlab:burning_board:2.0_rc2:*:*:*:*:*:*:* 9
cpe:2.3:a:woltlab:burning_board:2.0_rc1:*:*:*:*:*:*:* 9
cpe:2.3:a:woltlab:burning_board:1.1.1:*:*:*:*:*:*:* 9
cpe:2.3:a:woltlab:burning_board:2.2.1:*:*:*:*:*:*:* 8
cpe:2.3:a:woltlab:burning_board:2.3.0:*:*:*:*:*:*:* 8
cpe:2.3:a:woltlab:burning_board:2.3.3:*:*:*:*:*:*:* 7
cpe:2.3:a:woltlab:burning_board:2.3.4:*:*:*:*:*:*:* 7
cpe:2.3:a:woltlab:burning_board:2.2.3:*:*:*:*:*:*:* 7
cpe:2.3:a:woltlab:burning_board:2.0:*:*:*:*:*:*:* 7
cpe:2.3:a:woltlab:burning_board:2.0.3:*:*:*:*:*:*:* 7
cpe:2.3:a:woltlab:burning_board:2.1.5:*:*:*:*:*:*:* 7
cpe:2.3:a:woltlab:burning_board:2.1.6:*:*:*:*:*:*:* 6
cpe:2.3:a:woltlab:burning_board:1.2:*:*:*:*:*:*:* 6
cpe:2.3:a:woltlab:burning_board:2.3.2:*:*:*:*:*:*:* 4
cpe:2.3:a:woltlab:burning_board:2.3.5:*:*:*:*:*:*:* 4
cpe:2.3:a:woltlab:burning_board:2.6:*:*:*:*:*:*:* 3
cpe:2.3:a:woltlab:burning_board:2.3.6:*:*:*:*:*:*:* 3
cpe:2.3:a:woltlab:burning_board:2.7:*:*:*:*:*:*:* 3
cpe:2.3:a:woltlab:burning_board:2.5:*:*:*:*:*:*:* 3
cpe:2.3:a:woltlab:burning_board:2.4:*:*:*:*:*:*:* 3
cpe:2.3:a:woltlab:burning_board:3.0.5:*:*:*:*:*:*:* 2
cpe:2.3:a:woltlab:burning_board:2.3.6_pl2:*:*:*:*:*:*:* 1
cpe:2.3:a:woltlab:burning_board:3.0.3_pl1:*:*:*:*:*:*:* 1
cpe:2.3:a:woltlab:burning_board:3.0.1:*:*:*:*:*:*:* 1

Related : CVE

This CPE Product have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
  Date Alert Description
6.8 2009-09-09 CVE-2008-7192

Cross-site request forgery (CSRF) vulnerability in index.php in WoltLab Burning Board (wBB) 3.0.1, and possibly other 3.x versions, allows remote attackers to hijack the authentication of users for requests that delete private messages via the pmID parameter in a delete action in a PM page, a different vulnerability than CVE-2008-0472.

5 2008-04-09 CVE-2008-1717

WoltLab Community Framework (WCF) 1.0.6 in WoltLab Burning Board 3.0.5 allows remote attackers to obtain the full path via invalid (1) page and (2) form parameters, which leaks the path from an exception handler when a valid class cannot be found.

4.3 2008-04-09 CVE-2008-1716

Cross-site scripting (XSS) vulnerability in WoltLab Community Framework (WCF) 1.0.6 in WoltLab Burning Board 3.0.5 allows remote attackers to inject arbitrary web script or HTML via the (1) page and (2) form parameters, which are not properly handled when they are reflected back in an error message.

7.5 2008-02-20 CVE-2008-0857

SQL injection vulnerability in index.php in WoltLab Burning Board 3.0.3 PL 1 allows remote attackers to execute arbitrary SQL commands via the sortOrder parameter to the PMList page.

4.3 2008-01-29 CVE-2008-0472

Cross-site request forgery (CSRF) vulnerability in modcp.php in Woltlab Burning Board (wBB) 2.3.6 PL2 allows remote attackers to delete threads as moderators or administrators via a thread_del action.

7.5 2007-03-20 CVE-2007-1518

SQL injection vulnerability in usergroups.php in Woltlab Burning Board (wBB) 2.x allows remote attackers to execute arbitrary SQL commands via the array index of the applicationids array.

4.3 2007-03-13 CVE-2007-1443

Multiple cross-site scripting (XSS) vulnerabilities in register.php in Woltlab Burning Board (wBB) 2.3.6 and Burning Board Lite 1.0.2pl3e allow remote attackers to inject arbitrary web script or HTML via the (1) r_username, (2) r_email, (3) r_password, (4) r_confirmpassword, (5) r_homepage, (6) r_icq, (7) r_aim, (8) r_yim, (9) r_msn, (10) r_year, (11) r_month, (12) r_day, (13) r_gender, (14) r_signature, (15) r_usertext, (16) r_invisible, (17) r_usecookies, (18) r_admincanemail, (19) r_emailnotify, (20) r_notificationperpm, (21) r_receivepm, (22) r_emailonpm, (23) r_pmpopup, (24) r_showsignatures, (25) r_showavatars, (26) r_showimages, (27) r_daysprune, (28) r_umaxposts, (29) r_dateformat, (30) r_timeformat, (31) r_startweek, (32) r_timezoneoffset, (33) r_usewysiwyg, (34) r_styleid, (35) r_langid, (36) key_string, (37) key_number, (38) disablesmilies, (39) disablebbcode, (40) disableimages, (41) field[1], (42) field[2], and (43) field[3] parameters. NOTE: a third-party researcher has disputed some of these vectors, stating that only the r_dateformat and r_timeformat parameters in Burning Board 2.3.6 are affected.

7.5 2007-01-19 CVE-2007-0388

SQL injection vulnerability in search.php in Woltlab Burning Board (wBB) 1.0.2 and earlier, and 2.3.6 and earlier in the 2.x series, allows remote attackers to execute arbitrary SQL commands via the boardids[1] and other boardids[] parameters.

7.5 2006-09-27 CVE-2006-5029

SQL injection vulnerability in thread.php in WoltLab Burning Board (wBB) 2.3.x allows remote attackers to obtain the version numbers of PHP, MySQL, and wBB via the page parameter. NOTE: this issue might be a forced SQL error. Also, the original report was disputed by a third party for 2.3.3 and 2.3.4.

6.8 2006-08-23 CVE-2006-4317

Cross-site scripting (XSS) vulnerability in attachment.php in WoltLab Burning Board (WBB) 2.3.5 allows remote attackers to inject arbitrary web script or HTML via a GIF image that contains URL-encoded Javascript.

7.5 2006-06-27 CVE-2006-3256

SQL injection vulnerability in report.php in Woltlab Burning Board (WBB) 2.3.1 allows remote attackers to execute arbitrary SQL commands via the postid parameter.

7.5 2006-06-27 CVE-2006-3255

SQL injection vulnerability in showmods.php in Woltlab Burning Board (WBB) 1.2 allows remote attackers to execute arbitrary SQL commands via the boardid parameter.

7.5 2006-06-27 CVE-2006-3254

SQL injection vulnerability in newthread.php in Woltlab Burning Board (WBB) 2.0 RC2 allows remote attackers to execute arbitrary SQL commands via the boardid parameter.

7.5 2006-06-24 CVE-2006-3220

SQL injection vulnerability in studienplatztausch.php in Woltlab Burning Board (WBB) 2.2.1 allows remote attackers to execute arbitrary SQL commands via the sid parameter.

7.5 2006-06-24 CVE-2006-3219

SQL injection vulnerability in thread.php in Woltlab Burning Board (WBB) 2.2.2 allows remote attackers to execute arbitrary SQL commands via the threadid parameter.

7.5 2006-06-24 CVE-2006-3218

SQL injection vulnerability in profile.php in Woltlab Burning Board (WBB) 2.1.6 allows remote attackers to execute arbitrary SQL commands via the userid parameter.

7.5 2006-06-02 CVE-2006-2792

SQL injection vulnerability in misc.php in Woltlab Burning Board (WBB) 2.3.4 allows remote attackers to execute arbitrary SQL commands via the sid parameter.

7.5 2006-05-24 CVE-2006-2569

SQL injection vulnerability in links.php in 4R Linklist 1.0 RC2 and earlier, a module for Woltlab Burning Board, allows remote attackers to execute arbitrary SQL commands via the cat parameter.

6.8 2006-03-20 CVE-2006-1324

Cross-site scripting (XSS) vulnerability in acp/lib/class_db_mysql.php in Woltlab Burning Board (wBB) 2.3.4 allows remote attackers to inject arbitrary web script or HTML via the errormsg parameter when a SQL error is generated.

4.3 2006-03-13 CVE-2006-1215

Cross-site scripting (XSS) vulnerability in misc.php in Woltlab Burning Board (wBB) 2.3.4 allows remote attackers to inject arbitrary web script or HTML via the percent parameter. NOTE: this issue has been disputed in a followup post, although the original disclosure might be related to reflected XSS.

7.5 2006-03-09 CVE-2006-1094

SQL injection vulnerability in Datenbank MOD 2.7 and earlier for Woltlab Burning Board allows remote attackers to execute arbitrary SQL commands via the fileid parameter to (1) info_db.php or (2) database.php.

4.3 2006-03-07 CVE-2006-1034

Multiple cross-site scripting (XSS) vulnerabilities in Woltlab Burning Board (wBB) allow remote attackers to inject arbitrary web script or HTML via (1) the username parameter to galerie_index.php and possibly (2) galerie_onfly.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. The second vector might not be XSS.

2.6 2006-02-28 CVE-2006-0927

Multiple cross-site scripting (XSS) vulnerabilities in the JGS-XA JGS-Gallery Addon 4.0.0 and earlier for Woltlab Burning Board (wBB) 2.x allow remote attackers to inject arbitrary web script or HTML via the (1) userid parameter in (a) jgs_galerie_slideshow.php and (b) jgs_galerie_scroll.php, and the (2) katid parameter in (c) jgs_galerie_slideshow.php.

7.5 2005-08-23 CVE-2005-2673

SQL injection vulnerability in modcp.php in WoltLab Burning Board 2.2.2 and 2.3.3 allows remote authenticated attackers to execute arbitrary SQL commands via the (1) x or (2) y parameters.

7.5 2005-05-17 CVE-2005-1642

SQL injection vulnerability in the verify_email function in Woltlab Burning Board 2.x and earlier allows remote attackers to execute arbitrary SQL commands via the $email variable.

CWE : Common Weakness Enumeration

%idName
33% (2) CWE-352 Cross-Site Request Forgery (CSRF)
33% (2) CWE-79 Failure to Preserve Web Page Structure ('Cross-site Scripting')
16% (1) CWE-200 Information Exposure
16% (1) CWE-89 Improper Sanitization of Special Elements used in an SQL Command ('...

Open Source Vulnerability Database (OSVDB)

This CPE Product have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
id Description
59097 WoltLab Burning Board (wbboard) profile.php message Parameter CSRF
59096 WoltLab Burning Board (wbboard) reply.php message Parameter CSRF
56353 WoltLab Burning Board index.php Private Message Deletion CSRF
44266 WoltLab Community Framework (WCF) Multiple Parameter XSS
44265 WoltLab Community Framework (WCF) Multiple Variable Path Disclosure
41856 WoltLab Burning Board index.php sortOrder Parameter SQL Injection
40622 WoltLab Burning Board modcp.php thread_del Action CSRF
33873 WoltLab Burning Board usergroups.php applicationids Array SQL Injection
33872 WoltLab Burning Board search.php Multiple Parameter SQL Injection
33871 WoltLab Burning Board register.php Multiple Parameter XSS
32033 WoltLab Burning Board thread.php page Variable Forced SQL Error Information D...
31205 WoltLab Burning Board galerie_onfly.php XSS
31204 WoltLab Burning Board galerie_index.php username Parameter XSS
28455 WoltLab Burning Board misc.php percent Parameter XSS
28126 WoltLab Burning Board File Attachment XSS
27471 WoltLab Burning Board newthread.php boardid Parameter SQL Injection
27470 WoltLab Burning Board report.php postid Parameter SQL Injection
27469 WoltLab Burning Board showmods.php boardid Parameter SQL Injection
27468 WoltLab Burning Board profile.php userid Parameter SQL Injection
27467 WoltLab Burning Board studienplatztausch.php sid Parameter SQL Injection
27466 WoltLab Burning Board thread.php threadid Parameter SQL Injection
26574 WoltLab Burning Board misc.php sid Parameter SQL Injection
25751 WoltLab Burning Board links.php cat SQL Injection
23963 WoltLab Burning Board class_db_mysql.php SQL Error Message XSS
23810 Datenbank MOD for Woltlab Burning Board database.php fileid Parameter SQL Inj...

OpenVAS Exploits

id Description
2009-09-16 Name : WoltLab Burning Board Cross-Site Request Forgery Vulnerability
File : nvt/secpod_woltlab_burning_board_csrf_vuln.nasl
2008-10-24 Name : Woltlab Burning Board SQL injection flaw
File : nvt/burning_board_database_sql_injection.nasl

Nessus® Vulnerability Scanner

id Description
2007-01-18 Name: The remote web server contains a PHP script that is prone to a SQL injection ...
File: burning_board_boardids_sql_injection.nasl - Type: ACT_ATTACK
2006-03-08 Name: The remote web server contains a PHP script that is susceptible to SQL inject...
File: burning_board_database_sql_injection.nasl - Type: ACT_ATTACK
2005-08-30 Name: The remote web server contains a PHP script that is prone to SQL injection at...
File: burning_board_xy_sql_injection.nasl - Type: ACT_GATHER_INFO
2005-05-17 Name: The remote web server contains a PHP script that is prone to SQL injection at...
File: burning_board_verify_email_sql_injection.nasl - Type: ACT_ATTACK
2005-05-12 Name: The remote web server contains a PHP script which is vulnerable to a cross-si...
File: burning_board_pms_folderid_xss.nasl - Type: ACT_ATTACK