Marc Alexander

3 exploits Active since Feb 2015
CVE-2015-1431 WRITEUP WRITEUP
phpBB <3.0.13 - XSS
Cross-site scripting (XSS) vulnerability in includes/startup.php in phpBB before 3.0.13 allows remote attackers to inject arbitrary web script or HTML via vectors related to "Relative Path Overwrite."
CVE-2015-3880 WRITEUP MEDIUM WRITEUP
phpBB <3.0.14, <3.1.4 - Open Redirect
Open redirect vulnerability in phpBB before 3.0.14 and 3.1.x before 3.1.4 allows remote attackers to redirect users of Google Chrome to arbitrary web sites and conduct phishing attacks via unspecified vectors.
CVSS 6.1
CVE-2019-16993 WRITEUP HIGH WRITEUP
Phpbb < 3.1.7 - CSRF
In phpBB before 3.1.7-PL1, includes/acp/acp_bbcodes.php has improper verification of a CSRF token on the BBCode page in the Administration Control Panel. An actual CSRF attack is possible if an attacker also manages to retrieve the session id of a reauthenticated administrator prior to targeting them.
CVSS 8.8