VYPR

Asp Forum Script

by Codetoad

CVEs (2)

  • CVE-2008-6891Aug 3, 2009
    risk 0.03cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in ASP Forum Script allow remote attackers to inject arbitrary web script or HTML via the (1) forum_id parameter to (a) new_message.asp and (b) messages.asp, and the (2) query string to default.asp.

  • CVE-2008-6890Aug 3, 2009
    risk 0.03cvss epss 0.00

    SQL injection vulnerability in messages.asp in ASP Forum Script allows remote attackers to execute arbitrary SQL commands via the message_id parameter.