Baalasp maintains a focused portfolio of web-based application products, including its Smart Form Portal and forum platform, serving a specialized user base. The observed vulnerability signals center on generic application-layer issues; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Baalasp over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-6090HIGH Multiple SQL injection vulnerabilities in BaalAsp forum allow remote attackers to execute arbitrary SQL commands via the (1) password parameter to (a) adminlogin.asp, the (2) name | Nov 24, 2006 | 7.5 | 19 | NO | NO |
CVE-2006-6075MEDIUM Cross-site scripting (XSS) vulnerability in addpost1.asp in BaalAsp forum allows remote attackers to inject arbitrary web script or HTML via the name parameter. NOTE: The provenan | Nov 24, 2006 | 6.8 | 18 | NO | NO |
CVE-2006-6089MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in addpost1.asp in BaalAsp forum allow remote attackers to inject arbitrary web script or HTML via the (1) title (Subject), (2) | Nov 24, 2006 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Baalasp.
Media articles that mention a CVE ID that affects a product developed by Baalasp — matched by CVE ID, not by vendor name.