Snitz Communications Snitz Forums 2000 3.4.07

CPE Details

Snitz Communications Snitz Forums 2000 3.4.07
3.4.07
2010-01-05
11h24 +00:00
2012-10-12
11h30 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:snitz_communications:snitz_forums_2000:3.4.07:*:*:*:*:*:*:*

Informations

Vendor

snitz_communications

Product

snitz_forums_2000

Version

3.4.07

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2010-4826 2011-08-24 08h00 +00:00 SQL injection vulnerability in members.asp in Snitz Forums 2000 3.4.07 allows remote attackers to execute arbitrary SQL commands via the M_NAME parameter. NOTE: some of these details are obtained from third party information.
7.5
CVE-2010-4827 2011-08-24 08h00 +00:00 Cross-site scripting (XSS) vulnerability in members.asp in Snitz Forums 2000 3.4.07 allows remote attackers to inject arbitrary web script or HTML via the M_NAME parameter. NOTE: some of these details are obtained from third party information.
4.3
CVE-2009-4554 2010-01-04 20h00 +00:00 Multiple cross-site scripting (XSS) vulnerabilities in Snitz Forums 2000 3.4.07 allow remote attackers to inject arbitrary web script or HTML via (1) the url parameter to pop_send_to_friend.asp, related to a crafted onload attribute of an IMG element; or (2) an onload attribute in a sound tag.
4.3
CVE-2006-2530 2006-05-22 21h00 +00:00 avatar_upload.asp in Avatar MOD 1.3 for Snitz Forums 3.4, and possibly other versions, allows remote attackers to bypass file type checks and upload arbitrary files via a null byte in the file name, as discovered by the Codescan product.
5