Filtered by vendor Snitz Communications Subscriptions
Filtered by product Snitz Forums 2000 Subscriptions
Total 25 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2008-0136 1 Snitz Communications 1 Snitz Forums 2000 2024-08-07 N/A
Snitz Forums 2000 3.4.05 allows remote attackers to obtain sensitive information via a direct request to forum/whereami.asp, which reveals the database path.
CVE-2009-4554 1 Snitz Communications 1 Snitz Forums 2000 2024-08-07 N/A
Multiple cross-site scripting (XSS) vulnerabilities in Snitz Forums 2000 3.4.07 allow remote attackers to inject arbitrary web script or HTML via (1) the url parameter to pop_send_to_friend.asp, related to a crafted onload attribute of an IMG element; or (2) an onload attribute in a sound tag.
CVE-2010-4827 1 Snitz Communications 1 Snitz Forums 2000 2024-08-07 N/A
Cross-site scripting (XSS) vulnerability in members.asp in Snitz Forums 2000 3.4.07 allows remote attackers to inject arbitrary web script or HTML via the M_NAME parameter. NOTE: some of these details are obtained from third party information.
CVE-2010-4826 1 Snitz Communications 1 Snitz Forums 2000 2024-08-07 N/A
SQL injection vulnerability in members.asp in Snitz Forums 2000 3.4.07 allows remote attackers to execute arbitrary SQL commands via the M_NAME parameter. NOTE: some of these details are obtained from third party information.
CVE-2012-5313 1 Snitz Communications 1 Snitz Forums 2000 2024-08-06 N/A
SQL injection vulnerability in forum.asp in Snitz Forums 2000 allows remote attackers to execute arbitrary SQL commands via the TOPIC_ID parameter.