Vulnerabilities > Thewebforum

DATE CVE VULNERABILITY TITLE RISK
2006-01-09 CVE-2006-0135 Input Validation vulnerability in TheWebForum
SQL injection vulnerability in login.php in TheWebForum (twf) 1.2.1 allows remote attackers to execute arbitrary SQL commands and bypass login authentication via the username parameter (aka the u variable).
network
low complexity
thewebforum
7.5
2006-01-09 CVE-2006-0134 Input Validation vulnerability in TheWebForum
Cross-site scripting (XSS) vulnerability in register.php in TheWebForum (twf) 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the www parameter.
network
thewebforum
4.3