VendorsBattleaxe Softwarebttlxeforumall versions
Vulnerabilities

Battleaxe Software Bttlxeforum

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2003-0215
SQL injection vulnerability in bttlxeForum 2.0 beta 3 and earlier allows remote attackers to bypass authentication via the (1) username and (2) password fields, and possibly other fields.
Published 2003-04-26 · Modified
7.51 PoCEPSS 0.012
CVE-2005-1570
forum.asp in bttlxeForum 2.0 allows remote attackers to obtain full path information via a certain hex-encoded argument to the page parameter, possibly due to a SQL injection vulnerability.
Published 2005-05-14 · Modified
5.0EPSS 0.012
CVE-2006-0974
Cross-site scripting (XSS) vulnerability in failure.asp in Battleaxe bttlxeForum 2.0 allows remote attackers to inject arbitrary web script or HTML via the err_txt parameter.
Published 2006-03-03 · Modified
4.31 PoCEPSS 0.019