VYPR

Web Wiz Forums

by Web Wiz Forums

CVEs (4)

  • CVE-2019-25442HigFeb 22, 2026
    risk 0.49cvss 7.5epss 0.00

    Web Wiz Forums 12.01 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the PF parameter. Attackers can send GET requests to member_profile.asp with malicious PF values to extract sensitive…

  • CVE-2007-1548Mar 20, 2007
    risk 0.03cvss epss 0.02

    SQL injection vulnerability in functions/functions_filters.asp in Web Wiz Forums before 8.05a (MySQL version) does not properly filter certain characters in SQL commands, which allows remote attackers to execute arbitrary SQL commands via \"' (backslash double-quote quote)…

  • CVE-2006-5635Nov 1, 2006
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in forum/search.asp in Web Wiz Forums allows remote attackers to execute arbitrary SQL commands via the KW parameter.

  • CVE-2005-2228Jul 12, 2005
    risk 0.00cvss epss 0.01

    Web Wiz Forums 7.9 and 8.0 allows remote attackers to view message titles of a hidden forum.