Vulnerabilities > Jgbbs
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2007-03-13 | CVE-2007-1440 | SQL injection vulnerability in Jgbbs 3.0 SQL injection vulnerability in search.asp in JGBBS 3.0 Beta 1 allows remote attackers to execute arbitrary SQL commands via the author parameter. | 7.5 |
2007-01-05 | CVE-2007-0089 | Information Disclosure vulnerability in Jgbbs 3.0 jgbbs stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for db/bbs.mdb. | 7.5 |