Vulnerabilities (CVE)

Filtered by vendor Lokwa Subscribe
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2002-1880 1 Lokwa 1 Lokwabb 2024-02-04 5.0 MEDIUM N/A
LokwaBB 1.2.2 allows remote attackers to read arbitrary messages by modifying the pmid parameter to pm.php.
CVE-2002-1879 1 Lokwa 1 Lokwabb 2024-02-04 7.5 HIGH N/A
SQL injection vulnerability in LokwaBB 1.2.2 allows remote attackers to execute arbitrary SQL commands via the (1) member parameter to member.php or (2) loser parameter to misc.php.