Vulnerabilities > MAX Kervin

DATE CVE VULNERABILITY TITLE RISK
2009-07-05 CVE-2009-2329 Information Exposure vulnerability in MAX Kervin Kervinet Forum
KerviNet Forum 1.1 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) admin/head.php, or (2) voting_diagram.php, (3) voting.php, (4) topics_search.php, (5) topics_list.php, (6) top_part.php, (7) quick_search.php, (8) quick_reply.php, (9) moder_menu.php, (10) messages_list.php, (11) menu.php, (12) head.php, (13) forums_list.php, (14) forum_statistics.php, (15) forum_info.php, or (16) birthday.php in include_files/, which reveals the installation path in an error message.
network
low complexity
max-kervin CWE-200
5.0
2009-07-05 CVE-2009-2328 Improper Authentication vulnerability in MAX Kervin Kervinet Forum
admin/edit_user.php in KerviNet Forum 1.1 and earlier does not require administrative authentication, which allows remote attackers to delete arbitrary accounts and conduct SQL injection attacks via the del_user_id parameter.
network
low complexity
max-kervin CWE-287
7.5
2009-07-05 CVE-2009-2327 Cross-Site Scripting vulnerability in MAX Kervin Kervinet Forum
Cross-site scripting (XSS) vulnerability in add_voting.php in KerviNet Forum 1.1 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the v_variant1 parameter.
network
max-kervin CWE-79
3.5
2009-07-05 CVE-2009-2326 SQL Injection vulnerability in MAX Kervin Kervinet Forum
Multiple SQL injection vulnerabilities in KerviNet Forum 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) an enter_parol cookie to index.php in an auto action or (2) the topic parameter to message.php.
network
low complexity
max-kervin CWE-89
7.5
2009-07-05 CVE-2007-6727 SQL Injection vulnerability in MAX Kervin Kervinet Forum
SQL injection vulnerability in topic.php in KerviNet Forum 1.1 allows remote attackers to execute arbitrary SQL commands via the forum parameter.
network
low complexity
max-kervin CWE-89
7.5