Vulnerabilities (CVE)

Filtered by vendor Discuz Subscribe
Filtered by product Discuz\!
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2009-4621 2 Discuz, Patching 2 Discuz\!, Jianghu Inn 2024-02-28 7.5 HIGH N/A
SQL injection vulnerability in the JiangHu Inn plugin 1.1 and earlier for Discuz! allows remote attackers to execute arbitrary SQL commands via the id parameter in a show action to forummission.php.
CVE-2008-6957 1 Discuz 1 Discuz\! 2024-02-28 7.5 HIGH N/A
member.php in Crossday Discuz! Board allows remote attackers to reset passwords of arbitrary users via crafted (1) lostpasswd and (2) getpasswd actions, possibly involving predictable generation of the id parameter.