
CVE-2003-1237
https://notcve.org/view.php?id=CVE-2003-1237
31 Dec 2003 — Cross-site scripting vulnerability (XSS) in WWWBoard 2.0A2.1 and earlier allows remote attackers to inject arbitrary HTML or web script via a message post. • http://archives.neohapsis.com/archives/bugtraq/2003-02/0274.html •

CVE-1999-0953 – WWWBoard 2.0 - 'passwd.txt' Remote Password Disclosure
https://notcve.org/view.php?id=CVE-1999-0953
16 Sep 1999 — WWWBoard stores encrypted passwords in a password file that is under the web root and thus accessible by remote attackers. • https://www.exploit-db.com/exploits/3065 •

CVE-1999-0954
https://notcve.org/view.php?id=CVE-1999-0954
16 Sep 1999 — WWWBoard has a default username and default password. • http://www.securityfocus.com/bid/649 •

CVE-1999-0930
https://notcve.org/view.php?id=CVE-1999-0930
03 Sep 1998 — wwwboard allows a remote attacker to delete message board articles via a malformed argument. • http://www.securityfocus.com/bid/1795 •