Vulnerabilities > WSN Forum > WSN Forum

DATE CVE VULNERABILITY TITLE RISK
2006-10-20 CVE-2006-5421 Unspecified vulnerability in WSN Forum WSN Forum
WSN Forum 1.3.4 and earlier allows remote attackers to execute arbitrary PHP code via a modified pathname in the pathtoconfig parameter that points to an avatar image that contains PHP code, which is then accessed from prestart.php.
network
low complexity
wsn-forum
7.5
2005-11-30 CVE-2005-3916 SQL Injection vulnerability in WSN Forum WSN Forum 1.21
SQL injection vulnerability in memberlist.php in WSN Forum 1.21 allows remote attackers to execute arbitrary SQL commands via the id parameter in a profile action.
network
low complexity
wsn-forum
7.5