Vulnerabilities > Xfairguy > Codeavalanche Freeforum

DATE CVE VULNERABILITY TITLE RISK
2006-06-09 CVE-2006-2927 HTML Injection vulnerability in Xfairguy Codeavalanche Freeforum 1.0
Multiple cross-site scripting (XSS) vulnerabilities in post.asp in CodeAvalanche FreeForum (aka CAForum) 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) msg_subject and (2) msg_body parameters.
network
xfairguy
4.3
2006-06-05 CVE-2006-2822 SQL-Injection vulnerability in Xfairguy Codeavalanche Freeforum 1.0
SQL injection vulnerability in admin/default.asp in Dusan Drobac CodeAvalanche FreeForum (aka CAForum) 1.0 allows remote attackers to execute arbitrary SQL commands via the password parameter.
network
low complexity
xfairguy
7.5