VendorsSitescapesitescape_forumall versions
Vulnerabilities

Sitescape Sitescape Forum

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2006-2676
Dispatch.cgi/_user/uservCard/ in SiteScape Forum 7.2 and possibly earlier generates different responses in a way that allows remote attackers to enumerate valid usernames.
Published 2006-05-31 · Modified
5.0EPSS 0.014
CVE-2006-2677
SiteScape Forum 7.2 and possibly earlier stores the avf.rc configuraiton file under the web document root with insufficient access control, which allows remote attackers to obtain sensitive path information.
Published 2006-05-31 · Modified
5.0EPSS 0.014
CVE-2007-3807
Multiple cross-site scripting (XSS) vulnerabilities in SiteScape Forum before 7.3 allow remote attackers to inject arbitrary web script or HTML via the user name field in the login procedure, and other unspecified vectors.
Published 2007-07-17 · Modified
2.6EPSS 0.013