Vikingboard is a niche board-management or administrative software product that, despite a modest disclosure volume, ranks among the more prominent vendors in its functional category. The product's vulnerability pattern is characterized by a high tendency toward public exploit availability, making disclosed issues a priority for rapid inventory and patching across installed instances. Current severity, in-the-wild exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vikingboard over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-6284HIGH Directory traversal vulnerability in admin.php in Vikingboard 0.1.2 allows remote authenticated administrators to include arbitrary files via a .. (dot dot) sequence in the act par | Dec 4, 2006 | 9.0 | 33 | NO | YES |
CVE-2007-4088MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Vikingboard 0.1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) id, (2) f, (3) quote, and (4) act | Jul 30, 2007 | 4.3 | 27 | NO | YES |
CVE-2006-4708MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Vikingboard 0.1b allow remote attackers to inject arbitrary web script or HTML via the (1) act parameter in (a) help.php and | Sep 12, 2006 | 6.8 | 27 | NO | YES |
CVE-2006-6282HIGH members.php in Vikingboard 0.1.2 allows remote attackers to trigger a forced SQL error via an invalid s parameter, a different vector than CVE-2006-4709. NOTE: might only be an ex | Dec 4, 2006 | 9.3 | 23 | NO | NO |
CVE-2006-4709MEDIUM SQL injection vulnerability in topic.php in Vikingboard 0.1b allows remote attackers to execute arbitrary SQL commands via the s parameter. | Sep 12, 2006 | 5.0 | 22 | NO | YES |
CVE-2007-4089MEDIUM Vikingboard 0.1.2 allows remote attackers to obtain sensitive information via the debug parameter to (1) forum.php, (2) cp.php, and possibly other unspecified components. | Jul 30, 2007 | 4.3 | 21 | NO | YES |
CVE-2007-4090MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Vikingboard 0.1.2 allow remote attackers to inject arbitrary web script or HTML via (1) the URI to inc/lib/screen.php or (2) | Jul 30, 2007 | 4.3 | 15 | NO | NO |
CVE-2006-6283MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Vikingboard 0.1.2 allow remote attackers to inject arbitrary web script or HTML via the subject field of (1) a private messag | Dec 4, 2006 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vikingboard.
Media articles that mention a CVE ID that affects a product developed by Vikingboard — matched by CVE ID, not by vendor name.