Vulnerabilities > Heybbs Project

DATE CVE VULNERABILITY TITLE RISK
2020-09-03 CVE-2020-25006 SQL Injection vulnerability in Heybbs Project Heybbs 1.2
Heybbs v1.2 has a SQL injection vulnerability in login.php file via the username parameter which may allow a remote attacker to execute arbitrary code.
network
low complexity
heybbs-project CWE-89
critical
9.8
2020-09-03 CVE-2020-25005 SQL Injection vulnerability in Heybbs Project Heybbs 1.2
Heybbs v1.2 has a SQL injection vulnerability in msg.php file via the ID parameter which may allow a remote attacker to execute arbitrary code.
network
low complexity
heybbs-project CWE-89
critical
9.8
2020-09-03 CVE-2020-25004 SQL Injection vulnerability in Heybbs Project Heybbs 1.2
Heybbs v1.2 has a SQL injection vulnerability in user.php file via the ID parameter which may allow a remote attacker to execute arbitrary code.
network
low complexity
heybbs-project CWE-89
critical
9.8