Icebb maintains a focused product line centered on its core platform, which has surfaced vulnerabilities centered on SQL injection and related input-handling weaknesses. Treat this as a compact vendor profile rather than a broad trend line; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Icebb over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-1725HIGH SQL injection vulnerability in index.php in IceBB 1.0-rc5 allows remote authenticated users to execute arbitrary SQL commands via the filename of an uploaded file to the avatar fun | Mar 28, 2007 | 9.3 | 33 | NO | YES |
CVE-2008-3416HIGH SQL injection vulnerability in modules/members.php in IceBB before 1.0-rc9.3 allows remote attackers to execute arbitrary SQL commands via the username parameter in a members actio | Jul 31, 2008 | 7.5 | 28 | NO | YES |
CVE-2007-6083HIGH SQL injection vulnerability in admin/index.php in IceBB 1.0-rc6 allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For HTTP header. | Nov 22, 2007 | 7.5 | 28 | NO | YES |
CVE-2007-1726MEDIUM Unrestricted file upload vulnerability in index.php in IceBB 1.0-rc5 allows remote authenticated users to upload arbitrary files via the avatar function, which can later be accesse | Mar 28, 2007 | 6.5 | 26 | NO | YES |
CVE-2008-4431HIGH SQL injection vulnerability in index.php in IceBB 1.0-rc9.3 and earlier allows remote attackers to execute arbitrary SQL commands via the skin parameter, probably related to an inc | Oct 3, 2008 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Icebb.
Media articles that mention a CVE ID that affects a product developed by Icebb — matched by CVE ID, not by vendor name.