Ubb.Threads
Vendor:
First CVE: Oct 21, 2004 · Active for 21 years
20
Total CVEs
More Total CVEs than 94% of tracked products
3.3
Avg CVEs / Year
Higher CVE frequency than 82% of tracked products
5.9
Avg CVSS
Higher Avg CVSS than 20% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Ubb.Threads over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 21, 2004
21 years ago
Most Recent CVE
Sep 23, 2012
5,052 days ago
CVE Severity & Scoring
Ubb.Threads20 CVEs
65%
35%
All CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network1 (5.0%)
Unknown19 (95.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (5.0%)
High0 (0.0%)
Unknown19 (95.0%)
User Interaction
None0 (0.0%)
Unknown19 (95.0%)
Required1 (5.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None1 (5.0%)
Unknown19 (95.0%)
Top CVEs
Signals from CVEs in this product scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-6970HIGH SQL injection vulnerability in dosearch.inc.php in UBB.threads 7.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the Forum[] array parameter. | Aug 13, 2009 | 7.5 | 31 | NO | YES |
CVE-2006-0545HIGH SQL injection vulnerability in showflat.php in Groupee (formerly known as Infopop) UBB.threads 6.3 and earlier allows remote attackers to execute arbitrary SQL commands via the Num | Feb 4, 2006 | 7.5 | 31 | NO | YES |
CVE-2007-1956HIGH SQL injection vulnerability in ubbthreads.php in Groupee UBB.threads 6.1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the C parameter. | Apr 11, 2007 | 7.5 | 28 | NO | YES |
CVE-2005-2058HIGH Multiple SQL injection vulnerabilities in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to execute arbitrary SQL commands via the Number parameter to (1) download.ph | Jun 29, 2005 | 7.5 | 28 | NO | YES |
CVE-2004-1622HIGH SQL injection vulnerability in dosearch.php in UBB.threads 3.4.x allows remote attackers to execute arbitrary SQL statements via the Name parameter. | Oct 21, 2004 | 7.5 | 28 | NO | YES |
CVE-2012-5104MEDIUM Cross-site scripting (XSS) vulnerability in forums/ubbthreads.php in UBB.threads 7.5.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the Loginname | Sep 23, 2012 | 4.3 | 25 | NO | YES |
CVE-2006-2568MEDIUM PHP remote file inclusion vulnerability in addpost_newpoll.php in UBB.threads 6.4 through 6.5.2 and 6.5.1.1 (trial) allows remote attackers to execute arbitrary PHP code via a URL | May 24, 2006 | 5.1 | 25 | NO | YES |
CVE-2006-5137MEDIUM Multiple direct static code injection vulnerabilities in Groupee UBB.threads 6.5.1.1 allow remote attackers to (1) inject PHP code via a theme[] array parameter to admin/doeditthem | Oct 3, 2006 | 5.1 | 23 | NO | YES |
CVE-2006-2675MEDIUM PHP remote file inclusion vulnerability in ubbt.inc.php in UBBThreads 5.x and 6.x allows remote attackers to execute arbitrary PHP code via a URL in the (1) thispath or (2) configd | May 30, 2006 | 5.1 | 23 | NO | YES |
CVE-2004-2510MEDIUM Cross-site scripting (XSS) vulnerability in showflat.php in Infopop UBB.Threads before 6.5 allows remote attackers to inject arbitrary web script or HTML via the Cat parameter. | Dec 31, 2004 | 4.3 | 22 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (20 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
12 CVEs
60.0% of CVEs· 93rd percentile
Social Chatter
Signals from CVEs in this product scope (20 CVEs).
Media Mentions
Signals from CVEs in this product scope (20 CVEs).
Top CNAs Publishing CVEs For Ubb.Threads
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 7.6 | 1 | 4.3 | 2.0% | 0 | 1 |
| 7.5.5 | 1 | 4.3 | 2.0% | 0 | 1 |
| 7.5.4 | 1 | 4.3 | 2.0% | 0 | 1 |
| 7.5.3 | 1 | 4.3 | 2.0% | 0 | 1 |
| 7.5.2 | 1 | 4.3 | 2.0% | 0 | 1 |
| 7.5.1 | 1 | 4.3 | 2.0% | 0 | 1 |
| 7.5 | 1 | 4.3 | 2.0% | 0 | 1 |
| 7.4.2 | 1 | 4.3 | 2.0% | 0 | 1 |
| 7.4.1 | 1 | 4.3 | 2.0% | 0 | 1 |
| 7.4 | 1 | 4.3 | 2.0% | 0 | 1 |
| 7.3.1 | 1 | 4.3 | 2.0% | 0 | 1 |
| 7.2 | 2 | 5.9 | 4.6% | 0 | 2 |
| 7.1 | 2 | 5.9 | 4.6% | 0 | 2 |
| 7.0 | 2 | 5.9 | 4.6% | 0 | 2 |
| 6.5.3 | 3 | 5.4 | 3.9% | 0 | 3 |
| 6.5.2_beta2 | 4 | 5.3 | 3.5% | 0 | 4 |
| 6.5.2 | 5 | 5.3 | 4.4% | 0 | 5 |
| 6.5.1.1 | 12 | 5.7 | 2.7% | 0 | 7 |
| 6.5.1 | 9 | 5.6 | 3.0% | 0 | 6 |
| 6.5 | 10 | 5.5 | 2.9% | 0 | 7 |