mfoxhacker

2 exploits Active since Aug 2006
CVE-2006-4010 EXPLOITDB text WRITEUP
Virtual War <= 1.5.0 - SQL Injection via Page Parameter
SQL injection vulnerability in war.php in Virtual War (Vwar) 1.5.0 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter. NOTE: other vectors are covered by CVE-2006-3139.
CVE-2006-4009 EXPLOITDB text WRITEUP
Virtual War <= 1.5.0 - Cross-Site Scripting via Page Parameter
Cross-site scripting (XSS) vulnerability in war.php in Virtual War (Vwar) 1.5.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the page parameter.