7.5
CVSSv2

CVE-2006-0669

Published: 13/02/2006 Updated: 17/05/2024
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in archive.asp in GA's Forum Light allow remote malicious users to execute arbitrary SQL commands via the (1) Forum and (2) pages parameter. NOTE: SecurityTracker says that the vendor has disputed this issue, saying that GA Forum Light does not use an SQL database. SecurityTracker's research indicates that the original problem could be due to a vbscript parsing error based on invalid arguments

Vulnerable Product Search on Vulmon Subscribe to Product

gasoft gas forum light

Exploits

source: wwwsecurityfocuscom/bid/16563/info GA's Forum Light is prone to an SQL-injection vulnerability This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploi ...