VendorsSnitz Communicationssnitz_forums_20003.4.05
Vulnerabilities

Snitz Communications Snitz Forums 2000 3.4.05

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2006-2959
SQL injection vulnerability in inc_header.asp in Snitz Forum 3.4.05 and earlier allows remote attackers to execute arbitrary SQL commands via the %strCookieURL%.GROUP parameter in a cookie.
Published 2006-06-12 · Modified
7.5EPSS 0.015
CVE-2008-0209
Open redirect vulnerability in Forums/login.asp in Snitz Forums 2000 3.4.06 and earlier allows remote attackers to redirect users to arbitrary web sites via a URL in the target parameter.
Published 2008-01-10 · Modified
5.8EPSS 0.011
CVE-2008-0135
Snitz Forums 2000 3.4.06 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for forum/snitz_forums_2000.mdb.
Published 2008-01-08 · Modified
5.01 PoCEPSS 0.025
CVE-2006-2530
avatar_upload.asp in Avatar MOD 1.3 for Snitz Forums 3.4, and possibly other versions, allows remote attackers to bypass file type checks and upload arbitrary files via a null byte in the file name, as discovered by the Codescan product.
Published 2006-05-22 · Modified
5.0EPSS 0.016
CVE-2008-0136
Snitz Forums 2000 3.4.05 allows remote attackers to obtain sensitive information via a direct request to forum/whereami.asp, which reveals the database path.
Published 2008-01-08 · Modified
5.0EPSS 0.012
CVE-2005-3411
Cross-site scripting (XSS) vulnerability in post.asp in Snitz Forums 2000 3.4.05 allows remote attackers to inject arbitrary web script or HTML via the type parameter in a Topic method.
Published 2005-11-01 · Modified
4.31 PoCEPSS 0.037
CVE-2008-0134
Cross-site scripting (XSS) vulnerability in Forums/setup.asp in Snitz Forums 2000 3.4.06 and earlier allows remote attackers to inject arbitrary web script or HTML via the MAIL parameter.
Published 2008-01-08 · Modified
4.3EPSS 0.011