cbcvebase.

Wired Community Software Wwwthreads vulnerabilities

4 known vulnerabilities affecting wired_community_software/wwwthreads.

Total CVEs
4
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2006-3909P4MEDIUMCVSS 6.8PoCv5.4vrc32006-07-27
CVE-2006-3909 [MEDIUM] CVE-2006-3909: Cross-site scripting (XSS) vulnerability in calendar.php in WWWthreads allows remote attackers to in Cross-site scripting (XSS) vulnerability in calendar.php in WWWthreads allows remote attackers to inject arbitrary web script or HTML via the week parameter.
nvd
CVE-2006-1958P4MEDIUMCVSS 6.4vrc32006-04-21
CVE-2006-1958 [MEDIUM] CVE-2006-1958: Multiple SQL injection vulnerabilities in WWWThreads RC 3 allow remote attackers to execute arbitrar Multiple SQL injection vulnerabilities in WWWThreads RC 3 allow remote attackers to execute arbitrary SQL commands via (1) the forumreferrer cookie to register.php and (2) the messages parameter in message_list.php.
nvd
CVE-2002-0223P4HIGHCVSS 7.5v5.0v5.0.6+2 more2002-05-16
CVE-2002-0223 [HIGH] CVE-2002-0223: Infopop UBB.Threads 5.4 and Wired Community Software WWWThreads 5.0 through 5.0.9 allows remote atta Infopop UBB.Threads 5.4 and Wired Community Software WWWThreads 5.0 through 5.0.9 allows remote attackers to upload arbitrary files by using a filename that contains an accepted extension, but ends in a different extension.
nvd
CVE-2006-5059P4MEDIUMCVSS 5.1≤ 5.4.2v5.4+1 more2006-09-28
CVE-2006-5059 [MEDIUM] CVE-2006-5059: Multiple cross-site scripting (XSS) vulnerabilities in WWWthreads 5.4.2 and earlier allow remote att Multiple cross-site scripting (XSS) vulnerabilities in WWWthreads 5.4.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the Cat parameter to (1) dosearch.php, (2) postlist.php, (3) showmembers.php, (4) faq_english.php, (5) online.php, (6) login.php, (7) newuser.php, (8) wwwthreads.php, (9) search.php, or (10) postlist.php.
nvd
Wired Community Software Wwwthreads vulnerabilities | cvebase