CVE Tools

Pblang

6 CVEs tracked since 2005. Since Mar 2005, none of them reached CISA KEV.

Pblang CVEs per month

Mar 2005 to Sep 2005. Point at a month, or focus the strip and use the arrow keys.
Pblang CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2005-0320
2005-04null or fewer
2005-05null or fewer
2005-06null or fewer
2005-07null or fewer
2005-08null or fewer
2005-0940

Products

The products that kept showing up in Pblang's monthly top three, with their CVEs summed over those months.

  1. Pblang62 months

Latest CVEs

The 10 most recently published vulnerabilities affecting Pblang.

  1. CVE-2007-3096Directory traversal vulnerability in login.php in PBLang (PBL) 4.67.16.a and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a ....6.8
  2. CVE-2007-1052PHP remote file inclusion vulnerability in index.php in PBLang (PBL) 4.60 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the dbpath parameter, a different vector tha...10.0
  3. CVE-2006-5062PHP remote file inclusion vulnerability in templates/pb/language/lang_nl.php in PBLang (PBL) 4.66z and earlier allows remote attackers to execute arbitrary PHP code via a URL in the temppath parame...7.5
  4. CVE-2005-2892Directory traversal vulnerability in setcookie.php in PBLang 4.65, and possibly earlier versions, allows remote attackers to read arbitrary files via ".." sequences and "%00" (trailing null byte) i...5.0
  5. CVE-2005-2893Direct static code injection vulnerability in setcookie.php in PBLang 4.65, and possibly earlier versions, allows remote attackers to execute arbitrary PHP code via the username (u parameter), whic...7.5
  6. CVE-2005-2895setcookie.php in PBLang 4.65, and possibly earlier versions, allows remote attackers to obtain sensitive information via a %00 (a null byte) in the u parameter, which reveals the path in an error m...5.0
  7. CVE-2005-2894Cross-site scripting (XSS) vulnerability in the user registration in PBLang 4.65, and possibly earlier versions, allows remote attackers to inject arbitrary web script or PHP via the location field.4.3
  8. CVE-2005-0631delpm.php in PBLang 4.63 allows remote authenticated users to delete arbitrary PM files by modifying the "id" and "a" parameters.2.1
  9. CVE-2005-0630sendpm.php in PBLang 4.63 allows remote authenticated users to read arbitrary files via a full pathname in the orig parameter.2.1
  10. CVE-2005-0526Multiple cross-site scripting (XSS) vulnerabilities in PBLang 4.65 allow remote attackers to inject arbitrary web script or HTML via (1) the search string to search.php, (2) the subject of a PM, wh...4.3

The record

Peak rank
#13 in Sep 2005
Busiest month shown
Sep 2005, 4 CVEs
Months with a KEV entry
0 since Mar 2005
Monthly snapshots
2 since 2005
Pblang's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store