Webwizguide's vulnerability profile centers on a line of web-publishing and community-engagement applications including forums, guestbooks, and rich-text editors, with the durable signal reflecting application-layer input-handling weaknesses such as cross-site scripting, SQL injection, and cross-site request forgery. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Webwizguide over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-1548HIGH SQL injection vulnerability in functions/functions_filters.asp in Web Wiz Forums before 8.05a (MySQL version) does not properly filter certain characters in SQL commands, which all | Mar 20, 2007 | 7.5 | 28 | NO | YES |
CVE-2003-1571MEDIUM Web Wiz Guestbook 6.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database and obtain sensitive | Apr 2, 2009 | 5.0 | 24 | NO | YES |
CVE-2008-3391MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Web Wiz Forum 9.5 allow remote attackers to inject arbitrary web script or HTML via the mode parameter to (1) admin_group_det | Jul 31, 2008 | 4.3 | 21 | NO | YES |
CVE-2008-3392MEDIUM Cross-site request forgery (CSRF) vulnerability in Web Wiz Forum 9.5 allows remote attackers to log out a user via a link or IMG tag to log_off_user.asp. | Jul 31, 2008 | 5.8 | 16 | NO | NO |
CVE-2008-3367MEDIUM Cross-site scripting (XSS) vulnerability in RTE_popup_link.asp in Web Wiz Rich Text Editor (RTE) 3.x and 4.x before 4.03 allows remote attackers to inject arbitrary web script or H | Jul 30, 2008 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Webwizguide.
Media articles that mention a CVE ID that affects a product developed by Webwizguide — matched by CVE ID, not by vendor name.