Total vulnerabilities in the database
members.asp in Snitz Forums 2000 version 3.3.03 and earlier allows remote attackers to execute arbitrary code via a SQL injection attack on the parameters (1) M_NAME, (2) UserName, (3) FirstName, (4) LastName, or (5) INITIAL.
Software | From | Fixed in |
---|---|---|
snitz_communications / snitz_forums_2000 | 3.1-sr4 | 3.1-sr4.x |
snitz_communications / snitz_forums_2000 | 3.3.01 | 3.3.01.x |
snitz_communications / snitz_forums_2000 | 3.3.02 | 3.3.02.x |
snitz_communications / snitz_forums_2000 | 3.0 | 3.0.x |
snitz_communications / snitz_forums_2000 | 3.3 | 3.3.x |
snitz_communications / snitz_forums_2000 | 3.3.03 | 3.3.03.x |