VendorsVt-forumvt-forum_lite1.3
Vulnerabilities

Vt-forum Vt-forum Lite 1.3

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2006-6447
Multiple cross-site scripting (XSS) vulnerabilities in Vt-Forum Lite 1.3 and 1.5 allow remote attackers to inject arbitrary web script or HTML via (1) the StrMes parameter in vf_info.asp and possibly (2) a URL in the SRC attribute of an IFRAME element that is submitted to vf_newtopic.asp.
Published 2006-12-10 · Modified
6.82 PoCEPSS 0.020
CVE-2006-6449
Vt-Forum Lite 1.3 and earlier store sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/forum.mdb. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
Published 2006-12-10 · Modified
6.4EPSS 0.011