Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown

CVE-2008-6890

Disclosure Date: August 03, 2009 (last updated October 04, 2023)
SQL injection vulnerability in messages.asp in ASP Forum Script allows remote attackers to execute arbitrary SQL commands via the message_id parameter.
0
Attacker Value
Unknown

CVE-2008-6891

Disclosure Date: August 03, 2009 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in ASP Forum Script allow remote attackers to inject arbitrary web script or HTML via the (1) forum_id parameter to (a) new_message.asp and (b) messages.asp, and the (2) query string to default.asp.
0
Attacker Value
Unknown

CVE-2008-6527

Disclosure Date: March 25, 2009 (last updated October 04, 2023)
SQL injection vulnerability in forum.asp in GO4I.NET ASP Forum 1.0 allows remote attackers to execute arbitrary SQL commands via the iFor parameter.
0
Attacker Value
Unknown

CVE-2007-0826

Disclosure Date: February 07, 2007 (last updated October 04, 2023)
SQL injection vulnerability in forum.asp in Kisisel Site 2007 allows remote attackers to execute arbitrary SQL commands via the forumid parameter.
0
Attacker Value
Unknown

CVE-2006-6089

Disclosure Date: November 24, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in addpost1.asp in BaalAsp forum allow remote attackers to inject arbitrary web script or HTML via the (1) title (Subject), (2) groupname (Group Name), or (3) detail (Message) field.
0
Attacker Value
Unknown

CVE-2006-2870

Disclosure Date: June 06, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in forum_search.asp in Intelligent Solutions Inc. ASP Discussion Forum allows remote attackers to inject arbitrary web script or HTML via the search variable.
0
Attacker Value
Unknown

CVE-2006-2807

Disclosure Date: June 05, 2006 (last updated October 04, 2023)
ASPwebSoft Speedy Asp Discussion Forum allows remote attackers to change the password of any account via a modified account id and possibly arbitrary values of the name, email, country, password, and passwordre parameters to profileupdate.asp.
0
Attacker Value
Unknown

CVE-2005-4165

Disclosure Date: December 11, 2005 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in ASP-DEV ASP Resources Forum allow remote attackers to execute arbitrary SQL commands via the (1) forum_id parameter to forum.asp, (2) unspecified parameters to register.asp, and (3) the "Search For" field in search.asp.
0
Attacker Value
Unknown

CVE-2005-3422

Disclosure Date: November 01, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in error.asp in ASP Fast Forum allows remote attackers to inject arbitrary web script or HTML via the error parameter.
0
Attacker Value
Unknown

CVE-2001-0972

Disclosure Date: August 31, 2001 (last updated February 22, 2025)
Surf-Net ASP Forum before 2.30 uses easily guessable cookies based on the UserID, which allows remote attackers to gain administrative privileges by calculating the value of the admin cookie (UserID 1), i.e. "0888888."
0