Philboard is a web-based collaboration or bulletin-board platform whose vulnerability disclosures center on its core application and reflect classic web-application input-handling weaknesses including cross-site scripting, SQL injection, and related encoding issues. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Philboard over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-0920HIGH SQL injection vulnerability in philboard_forum.asp in Philboard 1.14 and earlier allows remote attackers to execute arbitrary SQL commands via the forumid parameter. | Feb 14, 2007 | 7.5 | 29 | NO | YES |
CVE-2008-5192HIGH SQL injection vulnerability in forum.asp in W1L3D4 Philboard 1.14 and 1.2 allows remote attackers to execute arbitrary SQL commands via the forumid parameter. NOTE: this might ove | Nov 21, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-5193MEDIUM Cross-site scripting (XSS) vulnerability in search.asp in W1L3D4 Philboard 1.14 and 1.2 allows remote attackers to inject arbitrary web script or HTML via the searchterms parameter | Nov 21, 2008 | 4.3 | 21 | NO | YES |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Philboard.
Media articles that mention a CVE ID that affects a product developed by Philboard — matched by CVE ID, not by vendor name.