← Vulnerability feed

Vulnerability record · CVE-2005-2059 · published 29 June 2005

CVE-2005-2059: Ubbcentral ubb.threads cross-site request forgery vulnerability

Ubbcentral · Ubb.Threads

Multiple cross-site request forgery (CSRF) vulnerabilities in (1) addaddress.php, (2) toggleignore.php, (3) removeignore.php, and (4) removeaddress.php in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to modify settings as another user via a link or IMG tag.

6.5 CVSS 3.1 Medium EPSS 0.96% · top 40.0% CWE-352 · Cross-site request forgery
6.5CVSS 3.1 base score, v2 5.0
0.96%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in (1) addaddress.php, (2) toggleignore.php, (3) removeignore.php, and (4) removeaddress.php in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to modify settings as another user via a link or IMG tag.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2005-2059 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2008-6970Ubbcentral ubb.threads sql injection vulnerabilitySQL injection vulnerability in dosearch.inc.php in UBB.threads 7.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the Fo…EPSS 7.3%7.5CVE-2007-1956Ubbcentral ubb.threads vulnerabilitySQL injection vulnerability in ubbthreads.php in Groupee UBB.threads 6.1.1 and earlier allows remote attackers to execute arbitrary SQL commands via …EPSS 0.98%7.5CVE-2006-5136Ubbcentral ubb.threads vulnerabilityMultiple PHP remote file inclusion vulnerabilities in ubbt.inc.php in Groupee UBB.threads 6.5.1.1 allow remote attackers to execute arbitrary PHP cod…EPSS 1.6%7.5CVE-2006-0545Ubbcentral ubb.threads vulnerabilitySQL injection vulnerability in showflat.php in Groupee (formerly known as Infopop) UBB.threads 6.3 and earlier allows remote attackers to execute arb…EPSS 1.3%7.5CVE-2005-2058Ubbcentral ubb.threads vulnerabilityMultiple SQL injection vulnerabilities in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to execute arbitrary SQL commands via the Numb…EPSS 1.2%7.5CVE-2005-0726Ubbcentral ubb.threads vulnerabilitySQL injection vulnerability in editpost.php in UBB.threads 6.0 allows remote attackers to execute arbitrary SQL commands via the Number parameter.EPSS 1.2%7.5CVE-2004-1622Ubbcentral ubb.threads vulnerabilitySQL injection vulnerability in dosearch.php in UBB.threads 3.4.x allows remote attackers to execute arbitrary SQL statements via the Name parameter.EPSS 2.4%6.8CVE-2005-2057Ubbcentral ubb.threads vulnerabilityMultiple cross-site scripting (XSS) vulnerabilities in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to inject arbitrary web script or…EPSS 1.5%

Source: NIST National Vulnerability Database (record CVE-2005-2059), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.