VYPR

Snitz Forums 2000

Sign in to watch

by Snitz Communications

CVEs (24)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2006-29590.000.01Jun 12, 2006SQL injection vulnerability in inc_header.asp in Snitz Forum 3.4.05 and earlier allows remote attackers to execute arbitrary SQL commands via the %strCookieURL%.GROUP parameter in a cookie.
CVE-2003-04930.000.00Aug 7, 2003Snitz Forums 3.4.03 and earlier allows attackers to gain privileges as other users by stealing and replaying the encrypted password after obtaining a valid session ID.
CVE-2003-04940.000.01Aug 7, 2003password.asp in Snitz Forums 3.4.03 and earlier allows remote attackers to reset passwords and gain privileges as other users by via a direct request to password.asp with a modified member id.
CVE-2003-02860.000.01Jun 16, 2003SQL injection vulnerability in register.asp in Snitz Forums 2000 before 3.4.03, and possibly 3.4.07 and earlier, allows remote attackers to execute arbitrary stored procedures via the Email variable.

Page 2 of 2