PT-2006-1725 · Ga · Ga'S Forum Light

Dj_Eyes

·

Published

2006-02-13

·

Updated

2024-08-07

·

CVE-2006-0669

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions GA's Forum Light (affected versions not specified)
Description The issue allows remote attackers to execute arbitrary SQL commands via the Forum and pages parameters in the archive.asp file. However, the vendor has disputed this issue, stating that GA Forum Light does not use an SQL database. Research suggests that the problem could be due to a vbscript parsing error based on invalid arguments.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Related Identifiers

CVE-2006-0669

Affected Products

Ga'S Forum Light