Vulnerabilities > Class 1

DATE CVE VULNERABILITY TITLE RISK
2005-12-31 CVE-2005-4640 SQL-Injection vulnerability in Poll Software
SQL injection vulnerability in index.php in class-1 Poll Software 0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) pollid or (2) previouspoll parameters.
network
low complexity
class-1
7.5
2005-09-14 CVE-2005-2902 SQL Injection vulnerability in Class-1 Forum
SQL injection vulnerability in class-1 Forum Software 0.24.4 allows remote attackers to execute arbitrary SQL commands and bypass the file extension check via SQL code in the file extension of an uploaded file.
network
low complexity
class-1
7.5
2005-07-19 CVE-2005-2323 SQL-Injection vulnerability in Class-1 Forum
Multiple SQL injection vulnerabilities in Class-1 Forum 0.24.4 and 0.23.2, and Clever Copy with forums installed, allow remote attackers to modify SQL statements via the (1) id parameter to viewattach.php, (2) viewuser_id parameter to users.php, or the (3) id or (4) forum parameter to viewforum.php.
network
low complexity
class-1 clever-copy
7.5
2005-07-19 CVE-2005-2322 Cross-Site Scripting vulnerability in Class-1 Forum
Cross-site scripting (XSS) vulnerability in Class-1 Forum 0.24.4 and 0.23.2, and Clever Copy with forums installed, allows remote attackers to inject arbitrary web script or HTML via the (1) viewuser_id or (2) group parameter to users.php.
4.3