Vulnerabilities > Snitz Communications

DATE CVE VULNERABILITY TITLE RISK
2007-03-10 CVE-2007-1374 HTML Injection vulnerability in Snitz Communications Snitz Forums 2000 3.4.06
Cross-site scripting (XSS) vulnerability in pop_profile.asp in Snitz Forums 2000 3.4.06 allows remote attackers to inject arbitrary web script or HTML via the MSN parameter.
4.3
2007-02-21 CVE-2007-1023 SQL Injection vulnerability in Snitz Communications Snitz Forums 2000 3.1
SQL injection vulnerability in pop_profile.asp in Snitz Forums 2000 3.1 SR4 allows remote attackers to execute arbitrary SQL commands via the id parameter.
network
low complexity
snitz-communications
7.5
2006-10-30 CVE-2006-5603 SQL Injection vulnerability in Snitz Communications Snitz Forums 2000 3.4.06
SQL injection vulnerability in pop_mail.asp in Snitz Forums 2000 3.4.06 allows remote attackers to execute arbitrary SQL commands via the RC parameter.
network
low complexity
snitz-communications
7.5
2006-09-14 CVE-2006-4796 Cross-Site Scripting vulnerability in Snitz Communications Snitz Forums 2000 3.4.06
Cross-site scripting (XSS) vulnerability in forum.asp in Snitz Forums 2000 3.4.06 allows remote attackers to inject arbitrary web script or HTML via the sortorder parameter (strtopicsortord variable).
4.3
2006-06-12 CVE-2006-2959 SQL Injection vulnerability in Snitz Forums inc_header.ASP
SQL injection vulnerability in inc_header.asp in Snitz Forum 3.4.05 and earlier allows remote attackers to execute arbitrary SQL commands via the %strCookieURL%.GROUP parameter in a cookie.
network
low complexity
snitz-communications
7.5
2006-05-22 CVE-2006-2530 Permissions, Privileges, and Access Controls vulnerability in Snitz Communications Avatar MOD 1.3
avatar_upload.asp in Avatar MOD 1.3 for Snitz Forums 3.4, and possibly other versions, allows remote attackers to bypass file type checks and upload arbitrary files via a null byte in the file name, as discovered by the Codescan product.
network
low complexity
snitz-communications CWE-264
5.0
2005-11-01 CVE-2005-3411 Cross-Site Scripting vulnerability in Snitz Communications Snitz Forums 2000 3.4.05
Cross-site scripting (XSS) vulnerability in post.asp in Snitz Forums 2000 3.4.05 allows remote attackers to inject arbitrary web script or HTML via the type parameter in a Topic method.
4.3
2004-12-31 CVE-2004-2720 Cross-Site Scripting vulnerability in Snitz Communications Snitz Forums 2000
Cross-site scripting (XSS) vulnerability in register.asp in Snitz Forums 2000 3.4.04 and earlier allows remote attackers to inject arbitrary web script or HTML via javascript events in the Email parameter.
4.3
2004-09-16 CVE-2004-1687 Unspecified vulnerability in Snitz Communications Snitz Forums 2000
CRLF injection vulnerability in down.asp for Snitz Forums 2000 3.4.04 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the location parameter.
network
low complexity
snitz-communications
5.0
2003-08-07 CVE-2003-0494 Unspecified vulnerability in Snitz Communications Snitz Forums 2000 3.4.03
password.asp in Snitz Forums 3.4.03 and earlier allows remote attackers to reset passwords and gain privileges as other users by via a direct request to password.asp with a modified member id.
network
low complexity
snitz-communications
critical
10.0