Ubb.Threads

Vendor:

First CVE: Oct 21, 2004 · Active for 21 years

20
Total CVEs
More Total CVEs than 94% of tracked products
3.3
Avg CVEs / Year
Higher CVE frequency than 82% of tracked products
5.9
Avg CVSS
Higher Avg CVSS than 20% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Ubb.Threads over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 21, 2004
21 years ago
Most Recent CVE
Sep 23, 2012
5,052 days ago

CVE Severity & Scoring

Ubb.Threads20 CVEs
All CVEs352,294 CVEs
MediumHigh
Attack Vector
Local0 (0.0%)
Network1 (5.0%)
Unknown19 (95.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (5.0%)
High0 (0.0%)
Unknown19 (95.0%)
User Interaction
None0 (0.0%)
Unknown19 (95.0%)
Required1 (5.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None1 (5.0%)
Unknown19 (95.0%)

Top CVEs

Signals from CVEs in this product scope (20 CVEs).

20 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
SQL injection vulnerability in dosearch.inc.php in UBB.threads 7.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the Forum[] array parameter.
Aug 13, 20097.531NOYES
SQL injection vulnerability in showflat.php in Groupee (formerly known as Infopop) UBB.threads 6.3 and earlier allows remote attackers to execute arbitrary SQL commands via the Num
Feb 4, 20067.531NOYES
SQL injection vulnerability in ubbthreads.php in Groupee UBB.threads 6.1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the C parameter.
Apr 11, 20077.528NOYES
Multiple SQL injection vulnerabilities in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to execute arbitrary SQL commands via the Number parameter to (1) download.ph
Jun 29, 20057.528NOYES
SQL injection vulnerability in dosearch.php in UBB.threads 3.4.x allows remote attackers to execute arbitrary SQL statements via the Name parameter.
Oct 21, 20047.528NOYES
Cross-site scripting (XSS) vulnerability in forums/ubbthreads.php in UBB.threads 7.5.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the Loginname
Sep 23, 20124.325NOYES
PHP remote file inclusion vulnerability in addpost_newpoll.php in UBB.threads 6.4 through 6.5.2 and 6.5.1.1 (trial) allows remote attackers to execute arbitrary PHP code via a URL
May 24, 20065.125NOYES
Multiple direct static code injection vulnerabilities in Groupee UBB.threads 6.5.1.1 allow remote attackers to (1) inject PHP code via a theme[] array parameter to admin/doeditthem
Oct 3, 20065.123NOYES
PHP remote file inclusion vulnerability in ubbt.inc.php in UBBThreads 5.x and 6.x allows remote attackers to execute arbitrary PHP code via a URL in the (1) thispath or (2) configd
May 30, 20065.123NOYES
Cross-site scripting (XSS) vulnerability in showflat.php in Infopop UBB.Threads before 6.5 allows remote attackers to inject arbitrary web script or HTML via the Cat parameter.
Dec 31, 20044.322NOYES

Exploit Exposure

Signals from CVEs in this product scope (20 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
12 CVEs
60.0% of CVEs· 93rd percentile

Social Chatter

Signals from CVEs in this product scope (20 CVEs).

Media Mentions

Signals from CVEs in this product scope (20 CVEs).

Top CNAs Publishing CVEs For Ubb.Threads

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
7.614.32.0%01
7.5.514.32.0%01
7.5.414.32.0%01
7.5.314.32.0%01
7.5.214.32.0%01
7.5.114.32.0%01
7.514.32.0%01
7.4.214.32.0%01
7.4.114.32.0%01
7.414.32.0%01
7.3.114.32.0%01
7.225.94.6%02
7.125.94.6%02
7.025.94.6%02
6.5.335.43.9%03
6.5.2_beta245.33.5%04
6.5.255.34.4%05
6.5.1.1125.72.7%07
6.5.195.63.0%06
6.5105.52.9%07