Skip to main content

Vendor/product archive

comscripts / cs-forum CVEs

Beta · best-effort

4 CVEs tagged to comscripts / cs-forum0 Critical, 1 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2006-3168

Published Jun 23, 2006

SQL injection vulnerability in CS-Forum before 0.82 allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) debut parameters in (a) read.php, and the (3)…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-3169

Published Jun 23, 2006

Multiple cross-site scripting (XSS) vulnerabilities in CS-Forum 0.81 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) msg_result and (2) rep_t…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3170

Published Jun 23, 2006

CS-Forum before 0.82 allows remote attackers to obtain sensitive information via unspecified manipulations, possibly involving an empty collapse[] or readall parameter to index.ph…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3171

Published Jun 23, 2006

CRLF injection vulnerability in CS-Forum before 0.82 allows remote attackers to inject arbitrary email headers via a newline character in the email parameter to ajouter.php.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1