Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown
CVE-2003-1571
Disclosure Date: April 02, 2009 (last updated October 04, 2023)
Web Wiz Guestbook 6.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database and obtain sensitive information via a direct request for database/WWGguestbook.mdb. NOTE: it was later reported that 8.21 is also affected.
0
Attacker Value
Unknown
CVE-2008-3392
Disclosure Date: July 31, 2008 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in Web Wiz Forum 9.5 allows remote attackers to log out a user via a link or IMG tag to log_off_user.asp.
0
Attacker Value
Unknown
CVE-2008-3391
Disclosure Date: July 31, 2008 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Web Wiz Forum 9.5 allow remote attackers to inject arbitrary web script or HTML via the mode parameter to (1) admin_group_details.asp and (2) admin_category_details.asp.
0
Attacker Value
Unknown
CVE-2008-3367
Disclosure Date: July 30, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in RTE_popup_link.asp in Web Wiz Rich Text Editor (RTE) 3.x and 4.x before 4.03 allows remote attackers to inject arbitrary web script or HTML via the email parameter.
0
Attacker Value
Unknown
CVE-2007-1548
Disclosure Date: March 20, 2007 (last updated October 04, 2023)
SQL injection vulnerability in functions/functions_filters.asp in Web Wiz Forums before 8.05a (MySQL version) does not properly filter certain characters in SQL commands, which allows remote attackers to execute arbitrary SQL commands via \"' (backslash double-quote quote) sequences, which are collapsed into \'', as demonstrated via the name parameter to forum/pop_up_member_search.asp.
0