RSS   Vulnerabilities for 'Wsn forum'   RSS

2006-10-20
 
CVE-2006-5421

 

 
WSN Forum 1.3.4 and earlier allows remote attackers to execute arbitrary PHP code via a modified pathname in the pathtoconfig parameter that points to an avatar image that contains PHP code, which is then accessed from prestart.php. NOTE: this issue has been labeled remote file inclusion, but that label only applies to the attack, not the underlying vulnerability.

 
2005-11-30
 
CVE-2005-3916

 

 
SQL injection vulnerability in memberlist.php in WSN Forum 1.21 allows remote attackers to execute arbitrary SQL commands via the id parameter in a profile action.

 


Copyright 2024, cxsecurity.com

 

Back to Top