Burning Board
Vendor:
First CVE: Oct 4, 2002 · Active for 23 years
31
Total CVEs
More Total CVEs than 97% of tracked products
4.4
Avg CVEs / Year
Higher CVE frequency than 88% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 32% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Burning Board over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 4, 2002
23 years ago
Most Recent CVE
Sep 9, 2009
6,165 days ago
CVE Severity & Scoring
Burning Board31 CVEs
39%
58%
All CVEs352,785 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown31 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown31 (100.0%)
User Interaction
None0 (0.0%)
Unknown31 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown31 (100.0%)
Top CVEs
Signals from CVEs in this product scope (31 CVEs).
31 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-2569HIGH SQL injection vulnerability in links.php in 4R Linklist 1.0 RC2 and earlier, a module for Woltlab Burning Board, allows remote attackers to execute arbitrary SQL commands via the c | May 24, 2006 | 7.5 | 31 | NO | YES |
CVE-2008-0857HIGH SQL injection vulnerability in index.php in WoltLab Burning Board 3.0.3 PL 1 allows remote attackers to execute arbitrary SQL commands via the sortOrder parameter to the PMList pag | Feb 21, 2008 | 7.5 | 28 | NO | YES |
CVE-2007-1518HIGH SQL injection vulnerability in usergroups.php in Woltlab Burning Board (wBB) 2.x allows remote attackers to execute arbitrary SQL commands via the array index of the applicationids | Mar 20, 2007 | 7.5 | 28 | NO | YES |
CVE-2007-0388HIGH SQL injection vulnerability in search.php in Woltlab Burning Board (wBB) 1.0.2 and earlier, and 2.3.6 and earlier in the 2.x series, allows remote attackers to execute arbitrary SQ | Jan 19, 2007 | 7.5 | 28 | NO | YES |
CVE-2006-3254HIGH SQL injection vulnerability in newthread.php in Woltlab Burning Board (WBB) 2.0 RC2 allows remote attackers to execute arbitrary SQL commands via the boardid parameter. | Jun 28, 2006 | 7.5 | 28 | NO | YES |
CVE-2006-3255HIGH SQL injection vulnerability in showmods.php in Woltlab Burning Board (WBB) 1.2 allows remote attackers to execute arbitrary SQL commands via the boardid parameter. | Jun 28, 2006 | 7.5 | 28 | NO | YES |
CVE-2006-3256HIGH SQL injection vulnerability in report.php in Woltlab Burning Board (WBB) 2.3.1 allows remote attackers to execute arbitrary SQL commands via the postid parameter. | Jun 28, 2006 | 7.5 | 28 | NO | YES |
CVE-2006-1094HIGH SQL injection vulnerability in Datenbank MOD 2.7 and earlier for Woltlab Burning Board allows remote attackers to execute arbitrary SQL commands via the fileid parameter to (1) inf | Mar 9, 2006 | 7.5 | 28 | NO | YES |
CVE-2005-2673HIGH SQL injection vulnerability in modcp.php in WoltLab Burning Board 2.2.2 and 2.3.3 allows remote authenticated attackers to execute arbitrary SQL commands via the (1) x or (2) y par | Aug 23, 2005 | 7.5 | 28 | NO | YES |
CVE-2005-1642HIGH SQL injection vulnerability in the verify_email function in Woltlab Burning Board 2.x and earlier allows remote attackers to execute arbitrary SQL commands via the $email variable. | May 17, 2005 | 7.5 | 28 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (31 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
18 CVEs
58.1% of CVEs· 91st percentile
Social Chatter
Signals from CVEs in this product scope (31 CVEs).
Media Mentions
Signals from CVEs in this product scope (31 CVEs).
Top CNAs Publishing CVEs For Burning Board
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.0.5 | 2 | 4.7 | 1.4% | 0 | 0 |
| 3.0.3_pl1 | 1 | 7.5 | 1.0% | 0 | 1 |
| 3.0.1 | 1 | 6.8 | 0.8% | 0 | 1 |
| 2.7 | 3 | 6.4 | 1.6% | 0 | 3 |
| 2.6 | 3 | 6.4 | 1.6% | 0 | 3 |
| 2.5 | 3 | 6.4 | 1.6% | 0 | 3 |
| 2.4 | 3 | 6.4 | 1.6% | 0 | 3 |
| 2.3.6_pl2 | 1 | 4.3 | 0.5% | 0 | 0 |
| 2.3.6 | 2 | 5.9 | 1.1% | 0 | 1 |
| 2.3.5 | 3 | 7.3 | 1.2% | 0 | 1 |
| 2.3.4 | 5 | 6.9 | 1.2% | 0 | 3 |
| 2.3.3 | 5 | 6.9 | 1.4% | 0 | 4 |
| 2.3.2 | 2 | 7.5 | 1.1% | 0 | 1 |
| 2.3.1 | 7 | 6.3 | 1.5% | 0 | 6 |
| 2.3.0 | 4 | 6.3 | 1.3% | 0 | 2 |
| 2.2.3 | 3 | 5.9 | 1.4% | 0 | 3 |
| 2.2.2 | 7 | 6.3 | 1.5% | 0 | 6 |
| 2.2.1 | 4 | 6.3 | 1.3% | 0 | 2 |
| 2.1.6 | 2 | 7.5 | 1.1% | 0 | 1 |
| 2.1.5 | 3 | 5.9 | 1.4% | 0 | 2 |