6kbbs is a web-based bulletin-board system whose vulnerability exposure centers on its single product and is defined by application-layer input and state-handling flaws, including cross-site scripting, SQL injection, and cross-site request forgery. Current severity, exploitation, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by 6kbbs over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-9292HIGH 6kbbs 7.1 and 8.0 allows CSRF via portalchannel_ajax.php (id or code parameter) or admin.php (fileids parameter). | Aug 8, 2019 | 8.8 | 22 | NO | NO |
CVE-2010-4812MEDIUM Multiple SQL injection vulnerabilities in 6kbbs 8.0 build 20100901 allow remote attackers to execute arbitrary SQL commands via the (1) tids[] parameter to ajaxadmin.php and the (2 | Jul 8, 2011 | 6.5 | 21 | NO | NO |
CVE-2010-4811MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in ajaxmember.php in 6kbbs 8.0 build 20100901 allow remote attackers to inject arbitrary web script or HTML via the (1) user[msn | Jul 8, 2011 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by 6kbbs.
Media articles that mention a CVE ID that affects a product developed by 6kbbs — matched by CVE ID, not by vendor name.