Pblang
6 CVEs tracked since 2005. Since Mar 2005, none of them reached CISA KEV.
Pblang CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2005-03 | 2 | 0 |
| 2005-04 | null or fewer | |
| 2005-05 | null or fewer | |
| 2005-06 | null or fewer | |
| 2005-07 | null or fewer | |
| 2005-08 | null or fewer | |
| 2005-09 | 4 | 0 |
Products
The products that kept showing up in Pblang's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 10 most recently published vulnerabilities affecting Pblang.
- CVE-2007-3096Directory traversal vulnerability in login.php in PBLang (PBL) 4.67.16.a and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a ....6.8
- CVE-2007-1052PHP remote file inclusion vulnerability in index.php in PBLang (PBL) 4.60 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the dbpath parameter, a different vector tha...10.0
- CVE-2006-5062PHP remote file inclusion vulnerability in templates/pb/language/lang_nl.php in PBLang (PBL) 4.66z and earlier allows remote attackers to execute arbitrary PHP code via a URL in the temppath parame...7.5
- CVE-2005-2892Directory traversal vulnerability in setcookie.php in PBLang 4.65, and possibly earlier versions, allows remote attackers to read arbitrary files via ".." sequences and "%00" (trailing null byte) i...5.0
- CVE-2005-2893Direct static code injection vulnerability in setcookie.php in PBLang 4.65, and possibly earlier versions, allows remote attackers to execute arbitrary PHP code via the username (u parameter), whic...7.5
- CVE-2005-2895setcookie.php in PBLang 4.65, and possibly earlier versions, allows remote attackers to obtain sensitive information via a %00 (a null byte) in the u parameter, which reveals the path in an error m...5.0
- CVE-2005-2894Cross-site scripting (XSS) vulnerability in the user registration in PBLang 4.65, and possibly earlier versions, allows remote attackers to inject arbitrary web script or PHP via the location field.4.3
- CVE-2005-0631delpm.php in PBLang 4.63 allows remote authenticated users to delete arbitrary PM files by modifying the "id" and "a" parameters.2.1
- CVE-2005-0630sendpm.php in PBLang 4.63 allows remote authenticated users to read arbitrary files via a full pathname in the orig parameter.2.1
- CVE-2005-0526Multiple cross-site scripting (XSS) vulnerabilities in PBLang 4.65 allow remote attackers to inject arbitrary web script or HTML via (1) the search string to search.php, (2) the subject of a PM, wh...4.3
The record
- Peak rank
- #13 in Sep 2005
- Busiest month shown
- Sep 2005, 4 CVEs
- Months with a KEV entry
- 0 since Mar 2005
- Monthly snapshots
- 2 since 2005