Vulnerabilities > ADN Forum

DATE CVE VULNERABILITY TITLE RISK
2006-01-09 CVE-2006-0124 Input Validation vulnerability in ADN Forum 1.0/1.0B
Cross-site scripting (XSS) vulnerability in crear.php in ADN Forum 1.0b allows remote attackers to inject arbitrary web script or HTML via the titulo parameter, which is used by the "Topic name" field.
network
adn-forum
4.3
2006-01-09 CVE-2006-0123 SQL Injection vulnerability in ADN Forum ADN Forum 1.0/1.0B
Multiple SQL injection vulnerabilities in ADN Forum 1.0b allow remote attackers to execute arbitrary SQL commands via the (1) fid parameter in index.php and (2) pagid parameter in verpag.php, and possibly other vectors.
network
low complexity
adn-forum CWE-89
7.5