CVEs (6)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Quicksilver Forums 1Quicksilver Forums Apr 23, 2026 Aug 25, 2009 N/A· v4 N/A· v3 7.5 HIGH· v2 Directory traversal vulnerability in the get_lang function in global.php in Quicksilver Forums 1.4.2 and earlier, as used in QSF Portal before 1.4.5, when running on Windows, allows remote attackers to include and execut...Show more |
1Quicksilver Forums 1Quicksilver Forums Apr 23, 2026 Aug 12, 2008 N/A· v4 N/A· v3 7.5 HIGH· v2 SQL injection vulnerability in index.php in Quicksilver Forums 1.4.1 allows remote attackers to execute arbitrary SQL commands via the forums array parameter in a search action. |
1Quicksilver Forums 1Quicksilver Forums Apr 23, 2026 Oct 1, 2007 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Quicksilver Forums before 1.4.1 allows remote attackers to obtain sensitive information by causing unspecified connection errors, which reveals the database password in the resulting error message. |
1Quicksilver Forums 1Quicksilver Forums Apr 23, 2026 Oct 1, 2007 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Unspecified vulnerability in Quicksilver Forums before 1.4.1 allows remote attackers to delete arbitrary PMs via unspecified vectors. |
1Quicksilver Forums 1Quicksilver Forums Apr 16, 2026 Sep 15, 2006 N/A· v4 N/A· v3 7.5 HIGH· v2 PHP remote file inclusion vulnerability in lib/activeutil.php in Quicksilver Forums (QSF) 1.2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the set[include_path] parameter. |
1Quicksilver Forums 1Quicksilver Forums Apr 16, 2026 Dec 6, 2005 N/A· v4 N/A· v3 5.1 MEDIUM· v2 SQL injection vulnerability in Quicksilver Forums before 1.5.1 allows remote attackers to execute arbitrary SQL commands via the HTTP_USER_AGENT header. |