VendorsSnitz Communicationssnitz_forums_20003.4.06
Vulnerabilities

Snitz Communications Snitz Forums 2000 3.4.06

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2006-5603
SQL injection vulnerability in pop_mail.asp in Snitz Forums 2000 3.4.06 allows remote attackers to execute arbitrary SQL commands via the RC parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
Published 2006-10-30 · Modified
9.81 PoCEPSS 0.014
CVE-2007-6240
SQL injection vulnerability in active.asp in Snitz Forums 2000 3.4.06 allows remote attackers to execute arbitrary SQL commands via the BuildTime parameter.
Published 2007-12-05 · Modified
7.51 PoCEPSS 0.010
CVE-2006-2530
avatar_upload.asp in Avatar MOD 1.3 for Snitz Forums 3.4, and possibly other versions, allows remote attackers to bypass file type checks and upload arbitrary files via a null byte in the file name, as discovered by the Codescan product.
Published 2006-05-22 · Modified
5.0EPSS 0.016
CVE-2006-4796
Cross-site scripting (XSS) vulnerability in forum.asp in Snitz Forums 2000 3.4.06 allows remote attackers to inject arbitrary web script or HTML via the sortorder parameter (strtopicsortord variable).
Published 2006-09-14 · Modified
4.31 PoCEPSS 0.025
CVE-2007-1374
Cross-site scripting (XSS) vulnerability in pop_profile.asp in Snitz Forums 2000 3.4.06 allows remote attackers to inject arbitrary web script or HTML via the MSN parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Published 2007-03-10 · Modified
4.3EPSS 0.010