Leszek Krupinski's disclosed vulnerabilities center on L-Forum, a focused web-application product, with the observed weakness signal characterized by input and validation issues typical of forum-based platforms. Current severity, exploitation activity, and exposure counts are shown in the live-stats panel alongside this summary.
The number and severity of CVEs published that impact products developed by Leszek Krupinski over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2002-1457HIGH SQL injection vulnerability in search.php for L-Forum 2.40 allows remote attackers to execute arbitrary SQL statements via the search parameter. | Jun 9, 2003 | 7.5 | 28 | NO | YES |
CVE-2002-1458HIGH Cross-site scripting vulnerability in L-Forum 2.40 and earlier, when the "Enable HTML in messages" option is on, allows remote attackers to insert arbitrary script or HTML via mess | Jun 9, 2003 | 7.5 | 19 | NO | NO |
CVE-2002-1459HIGH Cross-site scripting vulnerability in L-Forum 2.40 and earlier, when the "Enable HTML in messages" option is off, allows remote attackers to insert arbitrary script or HTML via mes | Jun 9, 2003 | 7.5 | 19 | NO | NO |
CVE-2002-1460MEDIUM L-Forum 2.40 and earlier does not properly verify whether a file was uploaded or if the associated variables were set by POST (attachment, attachment_name, attachment_size and atta | Jun 9, 2003 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Leszek Krupinski.
Media articles that mention a CVE ID that affects a product developed by Leszek Krupinski — matched by CVE ID, not by vendor name.